Skip to content

ccnm v0.11.0

Choose a tag to compare

@github-actions github-actions released this 07 Oct 03:46
· 99 commits to main since this release

这一版补的是真机验收(P62)最后查出来的几处,以及受管 Codex 会话的命令审批。
P62 在 2026-10-04 完成:两个 Provider 的受管闭环、外部 MCP、Machine API、
候选包的安装升级回退都在真机(macOS Agent → Debian 13 Runtime)上过了。

两台机器要一起升。 内部协议号没变(仍是 10),但两端版本号不同时
doctor 和起会话照样会报 CCNM_E_VERSION。ccnm.machine/1(ccnm rpc)
和 ccnm.workspace-mcp/1 仍是冻结的契约,这一版没有不兼容的改动。

受管 Codex 会话执行命令前问你(P71)

  • 以前 Codex 会话里模型调 exec_command 直接执行(Claude 会话每次都问)。
    现在 Agent 启动 Codex 前先问 Runtime 哪些工具要人确认,给它们单独设
    approval_mode="prompt":每次 exec_command 前弹 "Allow / Cancel",
    取消的调用到不了 Runtime。其余工具和 --print 不受影响。
  • 和 Claude 的区别:Codex 会话里的人用 /permissions 切到 Full Access 就
    不再问。workspace 的 allow_unattended_exec 对两边一样生效。
  • 只用 Codex 0.154.0 零额度实测过(本机假模型),没用真实模型跑过。

Machine API(P68,真机复验过)

  • Agent 上管运行的监督进程被杀,几秒内就是 unknown,failure 写明
    "监督进程没留下结局、Agent 可能还在跑"和它的 pid;以前要等满运行超时
    加 30 秒(默认 15 分半),这期间一直是 running。
  • 跑过的会话原始输出在第一次被读之前就没了,session.result 给旧尾部并带
    unavailable_reason: agent_refused,不再回"空且完整"。

doctor(P69、P70)

  • 对着旧版本的 Agent,先报版本不一致,不再只说"身份不符"。
  • Agent 是别的构建时,Reverse SSH 不再把它转述丢掉的字段算到 Runtime
    头上(旧 Agent 会让 Runtime 看起来"不是同一个构建")。
  • 版本行写实际的 Agent 节点名(以前写死 work)。
  • Command approval 一行按 Provider 说实话。

人用的 CLI(P69)

  • ccnm workspace add 按配置里的节点名写 runtime_node 和 Agent 节点,
    不再写死 agent/runtime;候选不止一个时用新参数 --agent-node 指定。

Two downloads, for the two halves of ccnm.

  • macos-universal — arm64 + x86_64. This is the one an Agent Node
    needs, and it also works as a Runtime.
  • linux-x86_64 — the Runtime half only (internal mcp-serve and its
    tools). The Agent half is a launchd LaunchAgent and does not run on
    Linux. Needs glibc >= 2.39; Debian 13 has 2.41.

Both machines need the same ccnm version.

Take the one for that machine -- a glob here would match both:

tar -xzf ccnm-<version>-<platform>.tar.gz
mv ccnm ~/.local/bin/ccnm.new && mv ~/.local/bin/ccnm.new ~/.local/bin/ccnm

Two things that bite:

  • Never cp over a ccnm that has already run. On Apple Silicon the next
    exec of it dies with SIGKILL (exit 137) while the running one carries on
    with the old code. Rename over it, as above.
  • Downloaded through a browser it arrives quarantined and macOS refuses to
    run it: xattr -d com.apple.quarantine ccnm. curl does not set that.

Setup, the doctor table and troubleshooting: README.md