Skip to content

ThinkReader 0.9.41

Choose a tag to compare

@zhangzejing zhangzejing released this 23 Sep 11:25
· 12 commits to main since this release

ThinkReader 0.9.41

Restore Agent paper-reading and annotation tools when a proxy intercepts local MCP connections.

Changes

  • All Agent CLI launches bypass proxies for localhost, 127.0.0.1 and ::1, while preserving existing bypass entries and external-service proxies. This fixes Codex reporting that ThinkReader tools are unavailable when its local MCP handshake receives a proxy error.
  • Cursor's native bridge explicitly bypasses proxies for its validated loopback connection, including in the packaged backend. Its UTF-8 protocol and connection-recovery checks now run with deliberately broken proxy settings.
  • Existing native sessions and Library data are preserved; no annotation migration is needed.

Validation

  • The implementation at 2b85f96ad09fa60d38363b67f1197de616b8cbb4 passed .\release-check.ps1 -Frontend on Windows on 2026-09-23: backend boundaries, backend files in separate processes, desktop regressions and the TypeScript/Vite production build. The proxy fix itself is ef7cdceffc39ab4679844622ea6719f07bc649dd.
  • Real authenticated Codex 0.153.0 read synthetic PDF evidence and saved a pinned annotation through ThinkReader services; the original PDF remained byte-identical. Extraction was synthetic; the CLI/model, MCP calls and annotation writes were real.
  • Real Cursor 2026.09.18-9a7762b discovered all six MCP tools with inherited and corrected proxy environments. Its frozen 0.9.4 bridge reproduced the failure under a deliberately broken proxy; the corrected source bridge passed.
  • Claude Code, Kimi, Hermes and DSH share the corrected launch environment. They were inspected in code but were not installed for real-provider acceptance.

Packaged validation

The exact build is build/release/ThinkReader-0.9.41-win-688c6484, from implementation commit 2b85f96ad09fa60d38363b67f1197de616b8cbb4. Later validation-document changes do not change the shipped application. Python commands below used build/packaging-venv/Scripts/python.exe.

  • python app/packaging/build_release.py --target win — passed. Frontend, backend and resource hashes match the build; updater installer name, size and SHA-512 passed validation. The frozen MCP bridge passed the broken-proxy, UTF-8 Chinese/math/emoji and connection-recovery checks.
  • python app/packaging/smoke_release.py --unpacked build/release/ThinkReader-0.9.41-win-688c6484 — passed startup, Profile persistence, PDF Range, annotation persistence/conflicts, output/image/summary protections, restart and original PDF integrity.
  • python build/release-audit/smoke_frozen_codex.py build/release/ThinkReader-0.9.41-win-688c6484 — a real Codex /browse task through the frozen backend's normal instruction API read a synthetic document, saved exactly one mainline area card and verified it was pinned. The original PDF remained byte-identical. The fixture used the Repository → Import → synthetic Extraction → Intelligence pipeline; no user paper was used. Local evidence: build/release-audit/codex-mcp-annotations-osvxjnap/frozen-report.json.
  • node build/release-audit/0.9.41-update/installed-update.cjs build/release/ThinkReader-0.9.41-win-688c6484 — an independently registered 0.9.4 installation detected, downloaded, validated and silently installed 0.9.41 from a loopback feed. All 1,571 installed resource files, including app.asar and the backend, matched the final candidate; an explicit restart reported 0.9.41 with a healthy backend. Differential download fell back to a full download because the local feed omitted the old blockmap. This checks the final application payload in a test installer with a separate executable name and registry identity; it does not establish byte-identical public-installer execution, differential download or automatic-restart acceptance. The original App was found closed after the test and was restarted at its unchanged 0.9.4 installation. Local evidence: build/release-audit/0.9.41-update/report.json.
  • ZIP inspection found both desktop entry points and no .git, .env, user-data or README_en.md entries.

SHA-256 of the release assets:

Asset SHA-256
latest.yml d49e2e558a51301ddc9686935de911a03573e5a9c09bcde041bd7aea0104d986
ThinkReader-0.9.41-win_x64.exe 91a16b48737f291646806f8940d13e2d4fbe4970c4295940cb4b1a3658945488
ThinkReader-0.9.41-win_x64.zip b9dcfcbb4f431dc8e8872fc73cd2566d157c870065ab36e872755c132412ed95
ThinkReader-Setup-0.9.41-win_x64.exe dda59c235ff86ee0fcde62ea252649692f9a652c8907507540c04d647a995818
ThinkReader-Setup-0.9.41-win_x64.exe.blockmap 8bd0dca7fcef85bb29622ec619218d29b6e34954f3c128ff280e5e708d09c618

Limits

  • Native-session metadata records Codex 0.153.0 for both the earlier successful session and the failure. The historical proxy process state was not recorded, so the exact external trigger is unproven.
  • Windows binaries are unsigned. Clean-machine installation and real-provider runs of the four unavailable CLIs are not covered.