Releases: virtualonno/papertiger
Release list
Papertiger 0.20.0
Planner schema v13 and Mise schema v10 are unchanged; no init is needed.
Upgrade as for 0.19.0: verify the archive against its published .sha256, then unpack it over the project root or run setup-project from the new binary.
Scripts that call note "text" must switch to note --text "text", and file: evidence passed to gate resolve or blocker resolve must now name an existing file beneath the project root.
Added
decompose <parent> --outline-file <path|->creates all of a parent's child tasks, with dependencies between them and on existing tasks, from onepapertiger.task_outline.v1JSON outline in a single transaction.
Outline keys wire the dependencies and are not stored; the receipt lists one task create event per child in outline order.
--start-readyalso starts the children whose dependencies are already done.
Any invalid entry, unknown reference, repeated tag or dependency, dependency cycle, dependency that waits for the parent, or duplicate title refuses the whole outline and lists every such problem in its entries.
An outline that repeats a JSON key in any object, exceeds 1 MiB or 256 children, or targets a finished parent or plan is refused on its own, naming the command or limit that fixes it.
Changed
- The installed agent contract and skill teach splitting a multi-part outcome with one
decomposecall instead of inventing section or phase labels, writing intents that stand alone rather than citing scratch or dated plan files, and operating each authority with its own project launcher. - Breaking:
notetakes its inline text as--text <text>, paired with--text-file <path|->like--why/--why-file; the positional text argument is gone.
Replacepapertiger note "text"withpapertiger note --text "text".
commit add --noteis unchanged. gate resolveandblocker resolverefuse a newfile:evidence locator that is absolute, leaves the project root, separates components with\, or does not name an existing regular file beneath it, with the same path rulesevidence verifyapplies, and with--sha256they refuse a digest that does not match the file's current bytes, naming the actual digest to pass instead.
The root is--project-rootor the discovered project.
With--db,PAPERTIGER_DBor the personal store there is no root, so pass--project-root <root>alongside the database override (now accepted for these two commands, as forevidence verify), or keep the text in the authority withnote --text-fileand resolve with a non-file locator such asnote:<summary>.
Stored locators and import are unaffected; other schemes are accepted as before.
Removed
- Mise's readers for the provenance-free campaign shapes:
papertiger-mise.campaign.v3with Git-patch candidate material, deterministic evaluator request and output v2, trial receipts v2–v4, materialization v3, candidate identity v2, paired analysis v2, paired trial request v3, and parent promotion proof v2.
Admission already accepted onlypapertiger-mise.campaign.v4, and no known Mise authority stores any of these records; one that did is now refused with the expected identifier.
Acampaign.v4manifest must declarecandidate_materialand each calibration'scandidate_material_sha256;campaign preflightand admission refuse a manifest that omits them or still carriescandidate_patch_sha256.
Every objective must bind a measurement contract, and every deterministic observation must carry its measurement provenance. - The v1 and v2 improvement-paradigm registries.
improvement verify-briefandimprovement compileread only the current built-in registry and refuse a brief bound to any other registry digest; rebind such a brief to the digest fromimprovement paradigms.
These registries were rewritten at the 0.18.0 schema-id cutover, so no brief written before 0.18.0 could bind them, and no known project authority holds a brief that does.
Fixed
- A project-install receipt naming another Papertiger release still refuses, but the refusal now names that project's own launcher,
<root>/tools/papertiger/bin/papertiger[.exe] --project-root <root>, for working in the authority as it is (or says the launcher is not installed on this host), before the deliberatepapertiger setup-project <root>upgrade. add --dep,dep addandedit --parentrefuse an edge that would leave tasks waiting on each other forever: a dependency on the task's own parent, on an ancestor of that parent, or on any task that depends on one of them, and a new parent whose completion the task already waits for.
Previously these were accepted, and neither the child nor the parent could ever start or complete until the edge was removed by hand.
The refusal shows the chain of dependencies and unfinished children that makes the tasks wait, and names thedep removecommand for each dependency in it.reopenrefuses a task that would make its parent wait for it forever, for example a retired child that gained a dependency on a task downstream of its parent, or a finished task moved under such a parent.
The refusal shows the chain and names theedit --parent,edit --clear-parentanddep removecommands that resolve it.auditreports adependency_deadlockfinding for each such loop an authority already holds, since older releases accepted these edges and import restores them unchanged.
The finding names thedep removecommands that break the loop.
Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Merge .agents, .claude, and tools into the project root. Skills are ready to discover; executables, documentation, licenses and the source manifest live under tools/papertiger.
Verify the adjacent SHA-256 asset before extraction.
Papertiger 0.19.0
Planner schema v13 and Mise schema v10 are unchanged; no init is needed.
Verify the archive against its published .sha256, then upgrade a project by unpacking the archive over the project root or by running setup-project from the new release binary, and a personal installation with setup-user.
Scripts that pass --replace-managed or check setup result schemas need updating.
Added
--project-root <root>selects an existing<root>/state/papertiger.sqlitewhen the root has neither a project-install receipt nor a release bundle, so a personal installation can reach a project's planning history without a committed Papertiger integration.
It still refuses when that file is absent, and discovery without--project-rootstill uses only receipts and bundles.
Changed
- Installed skills, the project reference and installed binaries are release files:
setup-projectandsetup-useroverwrite them with the release version, anduninstall-project/uninstall-userremove them, whether or not they were edited.
Keep project-specific guidance inAGENTS.mdorCLAUDE.md, which setup never touches. - Binaries are verified once, at download, against the release's
.sha256file; Papertiger no longer hashes installed binaries when it runs.
Project discovery,--project-root, release bundles and the personal runtime check only that the receipt or manifest names the running release (and, for the personal runtime, its home), and each refusal names the command that fixes it.
setup-projectstill replaces an installed binary that differs from the release binary running it. setup-projectno longer writes the host-localtools/papertiger/bin/papertiger[.exe].runtime-install.jsonreceipt, and removes one left by an earlier release.
Its result no longer hasruntime_receipt_pathorruntime_install, anduninstall-projectno longer lists that receipt.init --jsonnamesinit's plain-text report in its refusal instead of the generic "no JSON projection" message.- The project reference installed as
tools/papertiger/agent_integration.mdteaches planning use only; installation, upgrade and removal are in the README and--help. - Project receipts are
papertiger.project_install.v3and personal receiptspapertiger.user_install.v2; neither records file or binary hashes.
The nextsetup-projectorsetup-userrewrites a v2 project or v1 personal receipt.
An older receipt is refused: move it aside and rerun setup to reinstall. setup-projectreportspapertiger.project_install_result.v7,uninstall-projectreportspapertiger.project_uninstall.v3andsetup-userreportspapertiger.user_setup.v2; update scripts that check these schemas.
The uninstall result's only refusal action isnon_file_refusal, for a symlink or non-regular file at an owned path; it replacesmodified_refusal.- Mise refuses an unrecognized schema or protocol id by naming the id it expects.
papertiger_mise::schema_idsis no longer public. - Mise command messages consistently say "paired execution" (for example
paired recoveron an unknown id), and refusals raised by the authority's own integrity checks no longer end with a raw SQLite error code.
Removed
--replace-managedonsetup-projectandsetup-user.- Cleanup of files from pre-receipt project installations and release bundles with a
papertiger.release_manifest.v1manifest; reinstall such a project withsetup-projectfrom this release.
Fixed
setup-projectno longer reports a successful upgrade that leaves the project unusable.
Whentools/papertiger/manifest.jsonfrom an unpacked release archive names another release or cannot be read,setup-projectand--dry-runnow refuse before writing anything.
Before this fix, setup exited 0 and every later command refused the manifest.
To upgrade such a project, unpack the new release archive over the project root, or move the manifest aside and rerunsetup-project.
A custom authority path stays selected either way.
Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Merge .agents, .claude, and tools into the project root. Skills are ready to discover; executables, documentation, licenses and the source manifest live under tools/papertiger.
Verify the adjacent SHA-256 asset before extraction.
Papertiger 0.18.0
This release renames planner storage, commands, flags and JSON identifiers with no compatibility aliases.
To upgrade an authority, run papertiger --db <authority> backup --output <new-path> with the new binary, then papertiger init to migrate it from schema v12 to v13.
Until then commands that open the authority, other than init and backup, refuse it and name that command.
A Mise authority likewise needs papertiger-mise --db <database> init (schema v10).
Then update scripts for the renames below and rerun setup-project from the verified release binary so the project skill and reference match.
Changed
-
Release archives carry
papertiger.release_manifest.v3(waspapertiger.release-manifest.v2); update scripts that check the manifest schema. -
Blockers record a
condition:blocker add <task> <name> --condition <text>replaces--reason, and JSON, dumps and the database column usecondition. -
Gates use the blockers' vocabulary:
gate resolvereplacesgate close, and statusresolvedwithresolved_atreplacesclosedandclosed_at.
The migration converts stored gates.
Stored history keeps its original event kinds, so gate resolutions recorded before the upgrade still readclosedinlog. -
Exports are
papertiger.dump.v10.
importalso acceptspapertiger.dump.v9and converts it; older dumps still need their matching release to migrate and re-export. -
A raw SQLite writer now fails with
papertiger_write_requires_public_api(waspapertiger_write_requires_executable).
The migration reinstalls every guard. -
list --all-planspages with one opaque--after-cursortaken from the previous page'snext_cursororcontinuation_command;--after-seqand--snapshotare removed.
A cursor from different--status/--tagfilters or from a changed authority is refused with the restart command. -
Renamed flags and commands:
focus --include-blocked(was--all),evidence verify --classification(was--outcome), andpapertiger mise record(waspapertiger mise project). -
search --compactandshow --no-historyprint JSON without--json; both are JSON-only projections and previously refused the command. -
search --compactreturns 5 results by default (fullsearchkeeps 20) and includes acontinuation_commandwhen more results match. -
JSON ids are snake_case, with their version raised where the id or shape changed:
papertiger.task_context.v8,papertiger.task_current.v3,papertiger.task_inventory.v2(next_cursorandcontinuation_commandreplacesnapshotandnext_after_seq),papertiger.search_compact.v2,papertiger.evidence_verification.v3(projection.classificationreplacesprojection.outcome),papertiger.history_inspection.v2,papertiger.history_quarantine.v2,papertiger.mise_planner_projection.v2andpapertiger.project_install_result.v6(waspapertiger.project_setup.v5).
Quarantine envelopes and Mise projections recorded before this release keep their original ids and stay readable, exportable and importable;papertiger mise recordrefuses a new projection with the retired id and names the command that regenerates it. -
Help text names task arguments "Task number (N or #N)", no longer claims that
rejectprevents re-litigation (reopenaccepts rejected tasks), states thatexportcarries events and Mise projections, and documents thereference,historyand personal setup arguments. -
The project skill and reference are shorter.
commit addomits--repounless the commit belongs to a nested or external repository. -
Mise commands are renamed without aliases; the old spellings are refused.
paired run-next,show-runandlist-runsbecomeexecute-next,show-executionandlist-executions;improvement verify <FILE>becomesverify-registry;improvement brief-verifybecomesverify-brief;promotion inspectbecomespromotion rederive;projection inspectbecomesprojection export.
Update scripts and agent instructions that call them. -
Mise rationale flags are
--why <TEXT>or--why-file <PATH|->(stdin with-) instead of--reasononbudget release,candidate abandon-materialization,trial cancel,trial abandonandpaired cancel.
Cancellation requests report the rationale aswhy, and their JSONtargetfor a paired execution ispaired_execution. -
Mise authority schema v10 renames the recorded cancellation rationale to
whyand the recorded Papertiger gate time topapertiger_gate_resolved_at; promotion proofs and successor admissions report it asresolved_at.
Runpapertiger-mise --db <database> initonce after upgrading; read commands refuse a v9 authority and name that command. -
Every Mise schema, protocol and domain-separation id is
papertiger-mise.<snake_case_name>.v<N>with its version advanced, and the improvement formats move from thepapertiger.prefix topapertiger-mise..
Operator-authored inputs must be reissued under the new ids: campaign manifestspapertiger-mise.campaign.v4(measurement contractsmeasurement_contract.v2), adapter bindingspaired_adapter_binding.v2anddomain_shadow_adapter_binding.v2, fixture bundlesfixture_bundle.v2(regenerate withcampaign fixture-bundle), briefsproject_improvement_brief.v3, approvalsproject_improvement_brief_approval.v2and registriesimprovement_paradigm_registry.v2.
Deterministic evaluators must readdeterministic_evaluator_request.v3and emitdeterministic_evaluator_output.v3; paired adapters receivepaired_trial_request.v4.
Reruncampaign source-binding, because the repository identity digest changed with its domain-separation id.
The complete retired-to-current table ispapertiger_mise::schema_ids::RETIRED_SCHEMA_IDS. -
Mise containment policies are
ContainmentPolicywith schemapapertiger-mise.containment_policy.v3and protocolpapertiger-mise.ed25519_sealed.v3, replacingTrustedContainmentPolicyandpapertiger-mise.trusted-containment-policy.v2.
Reissue existing policy files; a retired policy is refused with that instruction.
Promotion proofs and sealed attestations name the policy digestcontainment_policy_sha256. -
Mise refuses campaigns, receipts and shadow evidence recorded before this release instead of reading them.
Each refusal names the replacement id; reopen frozen evidence with a 0.17.xpapertiger-mise, or admit a new campaign. -
Mise
--papertiger-dbdefaults tostate/papertiger.sqlite, resolved from--project-root, forcampaign admit-successor,promotion verify-parentandpromotion verify.
promotion verifypreviously required it. -
Mise
promotion deriveandpromotion verifyhelp states that both always refuse until sealed confirmation attestation lands. -
Planner Mise projections require candidate material
papertiger-mise.candidate_material.v2; export them with this release'spapertiger-mise projection export.
Removed
inspect-project-guidanceand theproject_guidancefield of the setup result.
Papertiger no longer recommends trigger text for a project'sAGENTS.mdorCLAUDE.md; installed skills route agents by their own descriptions.
Delete any Papertiger trigger text you added for it.
Fixed
- A trigger added by direct SQLite access is write-guard drift.
Previously it passedauditandrepair-guards --dry-run, then ran inside the next Papertiger mutation and could change planning data without an event.
Writes now refuse and name it;repair-guards --why <reason>removes it and records its SQL.
The Mise projection immutability triggers are also checked and restored.
An authority that already contains such a trigger refuses writes after upgrading untilrepair-guardsruns; reads, export and backup continue. repair-guards --jsonreports each entry'sstateasmissing,alteredorforeign.
Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Merge .agents, .claude, and tools into the project root. Skills are ready to discover; executables, documentation, licenses and the source manifest live under tools/papertiger.
Verify the adjacent SHA-256 asset before extraction.
Papertiger 0.17.1
No schema change; 0.17.0 authorities need no migration.
Fixed
- Missing or altered write guards no longer lock an authority.
Reads, export and backup continue,auditreports the drift, and writes refuse with the repair command.
repair-guards --dry-runpreviews the drift andrepair-guards --why <reason>reinstalls the guards and the canonical history view, recording what it found in an audited event.
It cannot write planning data.
Previously a single dropped trigger blocked status, export andinitwith no supported recovery. - The README and operating reference state the current schema as v12.
Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Merge .agents, .claude, and tools into the project root. Skills are ready to discover; executables, documentation, licenses and the source manifest live under tools/papertiger.
Verify the adjacent SHA-256 asset before extraction.
Papertiger 0.17.0
Upgrading migrates planner schema v10 or v11 to v12.
Read commands refuse the older schema and name the init command to run; take a backup first.
Changed
- Every planner table refuses writes from ordinary SQLite connections; use the executable or enter through the public mutation API.
Stored events are append-only, and normal opens refuse missing or altered guards.
This protects against raw-SQL misuse, not a filesystem owner deliberately defeating the guards.
Public API connections are trusted after mutation entry.
Added
history inspect <event-id>andhistory quarantine <event-id> --expect-sha256 <digest> --why <reason>recover structurally invalid legacy history after explicit review.
Original rows remain unchanged; an audited recovery event preserves every raw field through export/import.
Unknown timestamps and associations remain unknown, and task state is not inferred.
Fixed
auditidentifies every malformed stable event reference and reports oversized titles on terminal tasks, which can also block recovery imports.- Task reads identify priorities stored as text and name the recovery command.
After preserving a backup,edit <task> --priority <integer> --why <reason>can repair that value as an isolated edit, preserving the original text in arepair_priorityevent.
Reads never infer a numeric default, and other unreadable task fields roll back the repair. - Project skill guidance no longer points to an absent personal command binding.
First-use diagnostics preserve the selected authority instead of instructing project users to guess a database path.
Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Merge .agents, .claude, and tools into the project root. Skills are ready to discover; executables, documentation, licenses and the source manifest live under tools/papertiger.
Verify the adjacent SHA-256 asset before extraction.
Papertiger 0.16.0
The release archives were replaced with ready-to-use project overlays.
Download them again and verify the new checksums.
Merge .agents, .claude, and tools into the project root; executables and documentation have moved under tools/papertiger.
No setup command or project guidance rewrite is needed.
Existing configuration and planning data are not shipped or overwritten.
Added
setup-userinstalls a personal skill, native runtime and private fallback planner without changing consuming projects,AGENTS.md, shell profiles or harness settings.
The installed runtime discovers existing project authorities before using its private fallback, without a--dbargument.
Start a fresh agent session after installation; skill discovery does not guarantee model selection.uninstall-userremoves matching receipt-owned runtime and skills while retaining planner history.
Setup and removal support--dry-run; unowned or modified files require review and explicit replacement.
Missing expected history refuses setup.
Upgrade or repair from an external release binary.
Changed
- Every installed skill location contains the complete short workflow generated from one template.
Existing owned Claude routers upgrade in place, removing the extra read needed to reach executable bindings and operational guidance. - Direct project overlays are the default adoption path; personal installation remains optional.
setup-projectremains available for shared repository adoption and pinned runtimes; project guidance triggers are optional with skill-capable harnesses.
Cursor project markers select the shared skill in automatic setup. - The planning skill carries the ordinary workflow and loads installation, migration and less common operations from its reference only when needed.
Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Merge .agents, .claude, and tools into the project root. Skills are ready to discover; executables, documentation, licenses and the source manifest live under tools/papertiger.
Verify the adjacent SHA-256 asset before extraction.
Papertiger 0.15.0
Added
--session <id>andPAPERTIGER_SESSIONrecord advisory pickup when starting or resuming work.
focusprefers the caller's work and available alternatives over tasks last picked up by another session.
show,focus, andstatusexpose pickup identity and time without claiming that the agent is still alive.
Changed
focusis concise by default and preserves pickup, readiness, and blockers together.
JSON v7 replaces full task records with summaries, moves pickup toentries[].pickup, and reducesplanto slug and status.
Useshowfor intent, results, and history.startcan resume in-progress work without a release or takeover command.
Repeated pickup by the same identified session emits no event.
Pickup never blocks another session or guarantees exclusive execution; real dependencies, blockers, gates, and completion checks remain enforced.- Upgrading from 0.14.0 migrates planner schema v9 to v10 for pickup context.
Preserve an export and standalone backup before explicitly runninginit; migration does not infer sessions from historical actors.
Recovery dumps usepapertiger.dump.v9.
Changed read contracts are task context v7, current task v2, status v3, focus v7, and search v2.
Refresh consuming installations withsetup-project; keep old Mise drivers for campaigns that bind their executable identity. - Rust callers pass optional session context to
start_task,focus, andTaskCreation; passNonewhen no session identity is available. - JSON-schema verification runs in the Rust workspace tests without Python.
Removed
- Auxiliary Python scripts.
The historical native-value comparison document points to its archived runner and retains the original evidence and limitations.
Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Each contains the version-aligned papertiger and papertiger-mise binaries, setup and operating documentation, licenses, and a release manifest.
Verify the adjacent SHA-256 asset before extraction.
papertiger 0.14.0
Planner schema remains v9; upgrading from 0.13.0 needs no database migration.
Run setup-project from the new release to refresh project binaries and skills.
Keep the previous Mise driver for existing campaigns that bind its executable hash.
Added
list --all-plans --status unfinished --jsoninventories open tasks across every plan state, including paused plans, with owning plan identity, exact totals and bounded continuation.
Reuse the returned snapshot and unchanged filters for subsequent pages; changed authority history refuses continuation and requires restarting the inventory.plan list --jsonexposes structured plan orientation;--plan SLUGselects one plan.search --compact --jsonreturns ranked task summaries and excerpts without full bodies.
show --no-history --jsonreturns full current context with an explicit history command.
These opt-in projections usepapertiger.search_compact.v1andpapertiger.task_current.v1; existing full JSON reads retain their schemas.
Changed
- The installed skill uses compact discovery and current-state rechecks where appropriate while retaining full context for resumption.
Mutation guidance distinguishes optional task summaries from full task records and uses read-only recovery after a postcommit display failure.
Fixed
inspect-project-guidancerecognizes explicit@AGENTS.mdimports and directed local Markdown links inCLAUDE.mdas indirection.
This observation does not claim that imported instructions were loaded or followed.
Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Each contains the version-aligned papertiger and papertiger-mise binaries, setup and operating documentation, licenses, and a release manifest.
Verify the adjacent SHA-256 asset before extraction.
Papertiger 0.13.0
Planner schema remains v9; this update needs no database migration.
Retain the previous Mise driver for existing campaigns whose manifests bind its exact executable hash.
Added
- Planner mutations accept
--reasoning-effortorPAPERTIGER_REASONING_EFFORTalongside a known model.
Event history and task activity preserve the reported effort separately; existing events retain null effort without a database migration. - Mise
guidesupplies the running driver's concise agent workflow;guide --referenceemits its full operating reference without opening an authority. - Mise
campaign inspectdiscovers candidates, trials, paired cohorts, and reservations through bounded read-only pages.
Continuation arguments preserve project and database selection.
Recorded state remains separate from CAS verification and execution readiness.
Changed
- The vendored Papertiger skill contains the ordinary task workflow and loads installation, recovery, and advanced-operation detail only when needed.
Existing durable work remains tracked when its next step is a bounded edit or read-only check. - Agents are instructed to resolve the exact model variant and known reasoning effort once per execution context, then reuse those values until settings change.
- Claude skill installation uses a thin router to the canonical
.agents/skills/papertiger/SKILL.md.
Selecting Claude also installs that dependency; receipt-owned full copies upgrade automatically.
Fixed
- Task search results report the owning plan slug in
planinstead of the task status, including searches across multiple plans.
Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Each contains the version-aligned papertiger and papertiger-mise binaries, setup and operating documentation, licenses, and a release manifest.
Verify the adjacent SHA-256 asset before extraction.
Papertiger 0.12.1
Fixed
- The top-level
referencehelp describes task reference locators instead of repeating thecommitcommand description.
Prebuilt archives are attached for Windows x64, Linux x64, Intel macOS, and Apple Silicon macOS.
Each contains the version-aligned papertiger and papertiger-mise binaries, setup and operating documentation, licenses, and a release manifest.
Verify the adjacent SHA-256 asset before extraction.