跳到主要内容

RELEASE HISTORY

变更日志

变更日志

本文件记录项目所有值得注意的变更。

格式基于 Keep a Changelog,项目遵循语义化版本

[1.1] - 2026-08-08

组件版本

组件版本
copilot-shell2.8.0
agent-sec-core0.9.0
agentsight0.9.1
tokenless0.7.3
agent-memory0.2.6
os-skills0.6.1
anolisa0.2.15
skillfs0.4.0
ws-ckpt0.4.2
cosh-ng0.14.0

说明: os-skills 保持 v0.6.1,本次发布未更新;版本表保留该组件以展示完整组件组合。

重点特性

  • cosh-ng:更新到 v0.14.0,新增可恢复的 Workspace Session、MCP 管理、运行时状态查询和 DashScope Prompt Cache,Agent 可恢复长时间任务、扩展能力并降低重复 Prompt 成本(#1546、#1592、#1778、#1949、#2046)
  • agentsight:更新到 v0.9.1,新增优化与 Trajectory 分析以及 Case Containment、System Audit 和 ActPlane 风险执行,用户可诊断 Agent 质量与成本并调查、遏制风险行为(#1728、#1789、#2051)
  • agent-sec-core:更新到 v0.9.0,将 Prompt、PII、Code 和 Observability Hook 扩展到 Qoder CLI、Qwen Code 和 Codex,用户可在受支持的 Agent Runtime 间应用一致的安全策略(#1473、#1480、#1495、#1501、#1529、#1535)
  • tokenless:更新到 v0.7.3,新增带 MCP 检索的可逆压缩以及 Cosh-NG 响应与命令压缩,Agent 可减少 Model Context 并按需恢复被截断的内容(#1285、#1376、#1669)
  • anolisa:更新到 v0.2.15,新增精确版本 RPM/Raw 安装、文件元数据修复和交互式进度,管理员可选择已发布版本、修复安装漂移并查看操作阶段(#1700、#1740、#1987、#2036)

组件更新

  • copilot-shell:更新到 v2.8.0,新增需用户同意的 /ktuner 命令、导出 COSH_SESSION_ID 并在切换时复用兼容的 cosh-ng 认证,用户可调优主机、关联子进程活动并以更少配置在 Shell 间切换(#1279、#1491、#1951)
  • agent-sec-core:更新到 v0.9.0,新增 Qoder CLI 与 Qwen Code Hook 覆盖、Codex PII 与 Observability Hook、自定义 PII 规则及中文 Prompt Injection 检测,用户在 Prompt、Tool Call、Skill 和 Agent 输出上获得更广泛的保护(#1473、#1495、#1501、#1522、#1554)
  • agentsight:更新到 v0.9.1,新增 ATIF v1.7 Trajectory 分析、准确性/性能/成本 Workspace、Case Containment、System Audit 和风险 Dashboard,用户可追踪多 Agent 行为并处理优化或安全发现(#1728、#1789、#1828、#2051)
  • tokenless:更新到 v0.7.3,新增基于 Stash 的可逆压缩、MCP 检索服务器、Cosh-NG 压缩和 macOS/Qwencode Adapter 支持,Agent 可在更多 Runtime 中节省 Token 而不永久丢失压缩内容(#1285、#1376、#1669、#1894、#1964)
  • agent-memory:更新到 v0.2.6,新增同步索引以及聚焦 Query 和 OR 排序 Recall Fallback,Agent 可从冗长或包含较多停用词的 Prompt 中检索刚捕获的记忆(#1520、#1574、#2047)
  • anolisa:更新到 v0.2.15,新增精确版本 RPM/Raw 安装、Telemetry 控制、macOS arm64 npm 交付、文件元数据修复和分阶段进度,用户可跨 Linux 与 macOS 选择已发布版本、控制上报并修复 Linux 安装漂移(#1619、#1700、#1740、#1962、#1987、#2036)
  • skillfs:更新到 v0.4.0,新增 Hermes 嵌套 Skill 兼容、可配置读取时转换、认证的 Live Source 解析和强化的权限边界,Agent 可使用适配后的 Skill View,同时 Source Mutation 仍受安全控制(#1146、#1484、#1517)
  • ws-ckpt:更新到 v0.4.2,新增 Telemetry Gate 和孤立 Pre-init Backup 自动恢复,用户可在初始化中断后恢复 Workspace 而不受陈旧备份状态影响(#1509、#1601)
  • cosh-ng:更新到 v0.14.0,新增 Session 恢复、MCP Tool、Slash Command 状态查询和 Prompt Cache 可观测,Agent 可恢复复杂任务、扩展能力并诊断 Cache 节省效果(#1530、#1546、#1592、#1778、#1949、#2046、#2075)

[1.0] - 2026-07-06

组件版本

组件版本
copilot-shell2.6.1
agent-sec-core0.7.0
agentsight0.7.1
tokenless0.6.1
agent-memory0.2.1
os-skills0.6.1
anolisa0.1.20
skillfs0.3.2
ws-ckpt0.4.1
cosh-ng0.11.0

重点特性

  • anolisa:更新到 v0.1.20,交付统一 CLI 网关提供组件全生命周期管理与适配器编排,用户可通过一条命令安装/更新/诊断所有组件
  • cosh-ng:更新到 v0.11.0,完成 Core/Shell 分离与 AI 增强终端,Agent 可跨发行版确定性执行结构化系统操作
  • agent-memory:更新到 v0.2.1,新增用户数据主权与 4 类记忆分类,用户可查询/遗忘/控制自动捕获的记忆
  • tokenless:更新到 v0.6.1,新增压缩开关与 A/B 对比及 QwenCode 适配器,用户可量化各策略的 Token 节省效果而不影响任务执行

新增组件

  • anolisa:首次发布 v0.1.16,构建统一 CLI 网关管理组件安装/更新/卸载(RPM + Raw 双后端),用户可通过 anolisa install --all 一键部署全部组件
  • cosh-ng:首次发布 v0.11.0,实现确定性 Agent-OS 接口(5 crate workspace),Agent 可通过稳定 API 跨发行版执行结构化系统操作
  • skillfs:首次发布 v0.3.2,构建 FUSE 虚拟文件系统实现基于视图的 SKILL.md 暴露,Agent 可从挂载目录发现并加载技能

组件更新

  • agent-memory:更新到 v0.2.1,新增主权工具集(about/forget/consent)、AMA 导入导出、4 类分类和抗 SIGKILL 增量聚合,用户可自主控制记忆留存并跨 Agent 迁移
  • tokenless:更新到 v0.6.1,新增压缩开关(dry-run + 按模式统计)、SLS JSONL 遥测默认开启和 QwenCode 适配器,开发者可 A/B 测试压缩策略并在 SLS 大盘监控 Token 节省
  • agentsight:更新到 v0.7.1,新增 Token 节省可视化(策略饼图 + 行级 diff)、安全大盘和容器/K8s 全面支持,用户可直观评估各优化策略的节省贡献
  • copilot-shell:更新到 v2.6.1,新增 /model 多 Provider 切换对话框和 SLS 会话遥测(32 字段 JSONL),用户可自由切换 LLM Provider 而不丢失配置
  • agent-sec-core:更新到 v0.7.0,新增 Skill Ledger 完整性链(GPG 签名工作流)和 Prompt Scanner,用户可审计 Skill 安全状态并在危险操作前收到确认提示
  • os-skills:更新到 v0.6.1,新增 ANOLISA Guide 知识库 skill(13 份官方文档)和 OpenClaw 安装预检引导,Agent 可在回答中引用准确的产品文档
  • ws-ckpt:更新到 v0.4.1,新增自动清理调度和 TOML 配置热重载,用户可设置保留策略并即时生效无需重启 daemon

变更

  • 文档治理规范通过 specs/documentation-standard.md 建立
  • 双语命名约定统一为 _zh.md(从遗留 _CN.md 迁移)

[0.6] - 2026-06-12

组件版本

组件版本
copilot-shell2.4.1
agent-sec-core0.5.0
agentsight0.5.0
tokenless0.4.1
agent-memory0.1.0
os-skills0.5.0
cosh-ng0.1.0 (MVP)

重点特性

  • agent-memory:首次发布 v0.1.0,交付沙箱化文件系统 MCP 记忆服务器,Agent 可跨会话持久化存储并通过 BM25 检索上下文
  • tokenless:更新到 v0.4.1,新增 Hermes Agent 插件和 Tool Ready 4 阶段预检,Agent 工具执行前自动验证环境就绪避免无效重试
  • agentsight:更新到 v0.5.0,新增 Skill 维度 Token 指标和 Hermes 支持,用户可精确定位哪些 Skill 消耗最多 Token

新增组件

  • agent-memory:首次发布 v0.1.0,构建 19 工具 MCP 服务器(命名空间隔离 + BM25 后台索引),Agent 可在沙箱化文件系统中读写/检索持久记忆
  • cosh-ng:首次发布(MVP),完成确定性 OS 操作的生产可用功能,Agent 可获得格式可预测的结构化命令输出

组件更新

  • tokenless:更新到 v0.4.1,新增 Hermes adapter runner 和 Tool Ready 机制(4 阶段环境预检集成为 cosh extension),Agent 工具调用前自动校验环境减少因环境故障浪费的 Token
  • agentsight:更新到 v0.5.0,新增 Skill 维度 Token/调用指标和 Hermes matcher(含 SSL 支持),用户可在 Dashboard 中按 Skill 查看 Token 消耗明细
  • agent-sec-core:更新到 v0.5.0,新增 PIIChecker(输出 PII 检测 + 脱敏引擎)和 Skill Scanner(文本/代码扫描 + 生命周期触发),Agent 输出中的敏感信息被自动拦截
  • copilot-shell:更新到 v2.4.1,新增跨 Session 自动记忆提取和 hook reason UI 可见性,用户可看到安全 hook 拦截操作的具体原因

[0.5] - 2026-05-28

组件版本

组件版本
copilot-shell2.4.0
agent-sec-core0.4.0
agentsight0.4.0
tokenless0.4.0
os-skills0.4.0

重点特性

  • tokenless:更新到 v0.4.0,新增 Hermes 插件和 Tool Ready 环境机制,Agent 工具执行前依赖缺失被提前拦截避免 Token 浪费
  • agent-sec-core:更新到 v0.4.0,交付 PIIChecker 和 Skill Scanner 首版,Agent 输出被扫描防止敏感信息泄露

组件更新

  • tokenless:更新到 v0.4.0,开发 Hermes Agent 插件(Tool Ready 4 阶段环境预检 + History 压缩),Agent 运行时依赖在执行前被自动校验
  • agent-sec-core:更新到 v0.4.0,新增 PIIChecker 输出 PII 检测和 Skill Scanner 基线能力,用户免受 Agent 无意泄露敏感数据的风险
  • agentsight:更新到 v0.4.0,新增 Skill 维度指标展示,用户可按 Skill 查看 Token 消耗分组
  • os-skills:更新到 v0.4.0,纳入 Nightly 自动化测试覆盖,Skill 质量持续验证

[0.4] - 2026-05-13

组件版本

组件版本
copilot-shell2.3.0
agent-sec-core0.4.1
agentsight0.4.0
tokenless0.3.0
os-skills0.3.0
ws-ckpt0.2.0

重点特性

  • agent-sec-core:更新到 v0.4.1,建立 Skill 安全全生命周期管理(含 Prompt Scanner ask 策略),用户在 Agent 执行危险指令前收到确认提示
  • tokenless:更新到 v0.3.0,搭建 4 套 Benchmark 对比基线,开发者可量化评估不同 Skill/OS 环境的 Token 消耗差异
  • ws-ckpt:更新到 v0.2.0,扩展快照管理命令集,用户可按数量或时间维度自动清理历史快照

组件更新

  • agent-sec-core:更新到 v0.4.1,集成 Prompt Scanner 至 cosh hook 和 OpenClaw 插件(ask 策略),用户在危险操作前获得交互式确认
  • tokenless:更新到 v0.3.0,构建批量并发 Benchmark 平台并生成对比报告,开发者可一键跑分横向对比 Token 节省效果
  • agentsight:更新到 v0.4.0,优化常驻进程内存占用,2C2G 小规格实例可稳定运行可观测服务
  • copilot-shell:更新到 v2.3.0,适配 SWEBench 评测框架,开发者可通过 cosh 执行代码修复任务并验证通过率
  • ws-ckpt:更新到 v0.2.0,丰富快照增删查能力,用户可按策略自动保留最近 N 份快照

[0.3] - 2026-04-30

组件版本

组件版本
copilot-shell2.2.1
agent-sec-core0.3.0
agentsight0.3.1
tokenless0.2.0
os-skills0.3.0
ws-ckpt0.1.0

重点特性

  • tokenless:更新到 v0.2.0,交付命令重写和 TOON 上下文压缩,CLI 输出 Token 消耗降低 60–90%
  • agentsight:更新到 v0.3.1,新增 Token 节省 Dashboard 和 Agent 异常诊断,用户可可视化节省趋势并检测 Agent 中断
  • agent-sec-core:更新到 v0.3.0,新增 Skill Ledger 完整性追踪和 Prompt Scanner,每个 Skill 的签名链可端到端审计

新增组件

  • ws-ckpt:首次发布 v0.1.0,构建基于 btrfs 的工作区快照守护进程,Agent 可毫秒级创建检查点并即时回滚文件系统状态

组件更新

  • tokenless:更新到 v0.2.0,新增通过 RTK 的命令重写和 TOON 上下文压缩,Agent CLI 交互 Token 消耗减少 60–90%
  • agentsight:更新到 v0.3.1,新增 Token 节省 Dashboard(Session/时间段统计)和 Agent 中断检测(drain 机制),用户可监控节省趋势并在 Agent 故障时收到告警
  • agent-sec-core:更新到 v0.3.0,新增 Skill Ledger 全生命周期(check/certify/bypass/status/audit)和 Prompt Scanner 越狱检测,用户可追踪并强制执行 Skill 完整性策略
  • copilot-shell:更新到 v2.2.1,新增 Extension 架构(command extension + system Hook + 即时激活)、Skill 市场对接和会话导出(Markdown/HTML/JSON),用户可通过插件扩展 cosh 能力并导出对话历史
  • os-skills:更新到 v0.3.0,新增 Skill 市场上架和实用技能(xlsx/pdf-reader/image-gen/humanizer),用户可从市场发现并安装技能

[0.2] - 2026-04-15

组件版本

组件版本
copilot-shell2.0.4
agent-sec-core0.2.0
agentsight0.2.2
os-skills0.2.2
tokenless0.1.0

组件更新

  • agentsight:更新到 v0.2.2,新增 Token 消耗可观测(精确 Tokenizer 计量),用户可实时查看每条消息的 Token 明细
  • copilot-shell:更新到 v2.0.4,新增独立鉴权(STS/ECS RAM Role)和 Skill 市场浏览,用户无需 AK/SK 即可认证并发现可用技能
  • os-skills:更新到 v0.2.2,新增 SysAdmin 技能(Linux IO/网络/负载诊断),Agent 可独立诊断常见 OS 性能问题
  • tokenless:首次发布 v0.1.0,构建 Skills 级 Benchmark 测试用例,开发者可跨 Skill 量化对比 Token 消耗

[0.1] - 2026-03-30

组件版本

组件版本
copilot-shell2.0.1
agent-sec-core0.1
agentsight0.1
os-skills0.1

新增组件

  • copilot-shell:首次发布 v2.0.1,构建 AI 驱动终端助手(Tab 补全、/bash 模式、sudo、Hook 安全),用户开机即获得 AI 原生 CLI 交互体验
  • agent-sec-core:首次发布 v0.1,交付 Skill 签名校验、安全沙箱和系统加固,Agent 操作在受控最小权限环境中运行
  • agentsight:首次发布 v0.1,构建基于 eBPF 的零侵入可观测探针,用户无需修改 Agent 代码即可监控 LLM API 调用和 Token 消耗
  • os-skills:首次发布 v0.1,整理系统管理、SysOM 运维、DevOps 和云技能库,Agent 可自主执行常见 OS 操作

安全

  • Skill 全链路安全加密与数字签名
  • 硬件级安全沙箱风险隔离
  • Skill 调用身份认证与完整性校验

各组件详细变更日志请参阅:

用户入口

Token 节省

运行时

Agent 可观测

Agent 安全

更新日志

本项目的所有重要变更都会记录在此文件中。

本文档格式基于 Keep a Changelog, 项目遵循语义化版本

[0.2.6] - 2026-07-30

修复

  • agent-memory:更新到 v0.2.6,在短 token 的 LIKE 严格匹配无结果时改用 OR 匹配,并优先保留匹配更多关键词的结果,Agent 可从包含停用词的 prompt 中召回相关记忆而不再得到空结果(#2040)

[0.2.5] - 2026-07-27

修复

  • agent-memory:更新到 v0.2.5,从较长的英文和 CJK prompt 中生成聚焦的召回查询并合并结果,Agent 可从冗长 prompt 中召回相关记忆且不会静默遗漏主题(#1574)

0.2.4

  • fix(memory):修复 observe 后自动召回返回空结果的问题——memory_observe 后同步重建索引,使 before_prompt_build hook 能找到新内容(#1520)
  • fix(memory):install.sh 为 hook 设置 allowConversationAccess(#1521)

0.2.3

  • fix(memory):在 trigger 匹配和 hash 计算前,将 OpenClaw content block 数组 [{type:"text", text:"..."}] 规范化为字符串,避免自动捕获因内容被转换成 "[object Object]" 而失效
  • fix(memory):增加 BM25 OR fallback——当隐式 AND FTS5 查询返回 0 行且存在多个 token 时,使用 '\"token1\" OR \"token2\" OR ...' 重试,使部分匹配也能返回,而非静默失败
  • fix(memory):将 format!("{:.120}", query) 替换为 format!("bm25:len={}", query.len()),清理 audit_log,避免用户查询内容泄漏到日志路径

0.2.2

  • 修复 memory_observe hint 清理,使 YAML 转义的 hint 能通过不解析 YAML escape 的手写 frontmatter reader 往返读取:用 sanitize_hint() 替换 yaml_escape_hint(),仅将换行符和 ASCII 控制字符替换为空格;增加 8 个单元测试和一个真实 parser 往返测试,覆盖含反斜杠的 Windows 路径
  • MemoryConfig 增加 max_hint_bytes(默认 512)和 MEMORY_MAX_HINT_BYTES 环境变量覆盖;将 &MemoryConfig 贯穿 memory_observeMemoryService facade 和 MCP server
  • 修复 make install INSTALL_PROFILE=user PREFIX=$HOME/.localinstall-adapter-resources 阶段因 Permission denied 失败的问题:遵循 INSTALL_PROFILE 并从 $(PREFIX) 推导 DATADIR/SHARE_DIR,使所有可写路径均服从 profile(system 模式不变);与 tokenless/ws-ckpt 安装约定保持一致
  • 增加 safe_fs 安全边界单元测试(path escape、symlink traversal、sandbox root violation),并修复 cargo fmt --all --check 暴露的格式和 import order 问题

0.2.1

  • 修复配置 embedding provider 时 vector/hybrid search panic 和索引为空的问题:index worker 在没有 tokio Handle 的 std::thread 上运行,导致无法生成 embedding,而 memory_search mode=vector|hybrid 从 worker thread 调用 Handle::block_on;现在 spawn 时捕获 runtime handle 并传入 worker,search path 使用 block_in_place
  • 修复 memory_get_context.git 内部文件(如 .git/logs/HEAD)泄漏到 Agent context 的问题:通过 safe_fs 中共享的 is_under_git predicate 扩展 reserved-path filter,覆盖 .git/
  • 修复 full_scan(启动和 inotify overflow 恢复)只构建 BM25 index 而不生成 dense embedding,导致既有文件在修改前对 vector search 不可见的问题;新增 paths_without_vec 查询和 backfill pass,并将 embedding 逻辑集中到与 flush 共用的 embed_sync helper
  • 修复 memory_search 对短 CJK query term(少于 3 个字符,如“花名”/“小云”)返回 0 条结果的问题:trigram tokenizer 不会为少于 3 个字符的 term 生成 token,因此此类查询改用 body LIKE '%term%' substring scan,同时保留 recall、agent-scope filtering 以及 cold/superseded exclusion
  • 根据第一次真实 response 确定 embedding dimensions,不再硬编码 1536(DashScope text-embedding-v3 为 1024):维度存储在以估算值初始化的 AtomicUsize 中,并在首次 embed 时覆盖
  • 通过 .anolisa/component.toml 增加 anolisa-cli adapter contract,使 CLI adapter manager 能通过 [[adapters]] TOML schema 发现 OpenClaw plugin bundle

0.2.0

  • 增加 prompt injection 安全模块(looksLikePromptInjection + escapeMemoryForPrompt),Rust core 和 TS adapter 保持一致
  • 为安全模块增加 secret detection 和 PII redaction
  • 增加 auto-recall before_prompt_build hook,每轮注入相关 memory
  • 增加带 trigger filtering、SHA256 dedup 和 injection rejection 的 auto-capture agent_end hook
  • 通过可插拔 EmbeddingProvider 增加 dense-vector semantic search(OpenAI /v1/embeddings、Ollama /api/embed
  • 增加 files_vec table(schema v2),与 FTS5 BM25 一起存储 per-file dense embedding
  • 增加通过 reciprocal rank fusion(RRF,k=60)融合 BM25 和 vector score 的 hybrid search
  • memory_search 增加 mode 参数(bm25/vector/hybrid),并支持 graceful fallback 到 BM25
  • 通过 [memory].agent_scope(shared/isolated/filter,schema v5)增加 per-agent memory isolation
  • 增加带 consent.toml preference 的 memory sovereignty tool(memory_about/forget/auto_created/consent)
  • memory_observe 增加 4 类封闭 memory classification(user/feedback/project/reference)
  • 增加 mem_exportmem_import,用于跨 Agent memory migration(AMA archive format)
  • 增加用于 memory overview 和 source tracking 的 memory_summary tool
  • 增加 memory_session_context tool
  • 增加 memory_sessionsmemory_timeline session history query tool
  • 增加 MEMORY.md index file 和 mem_index_refresh tool
  • 增加 user profile synthesis(Dreaming V3 mem_dream
  • 增加 memory consolidation:shutdown 时从 session audit log 自动提取 L1 atomic fact
  • 从连贯的 tool-call chain 中增加 episodic memory extraction
  • 增加 cross-session task persistence 和 incremental consolidation
  • 增加 consolidation quality filter(mutual exclusion、non-derivable、date normalization)
  • 为 BM25/vector/hybrid score 增加 time-decay ranking(exp(-λ×age_days))
  • 使用 mem_compact tool 对长期从未访问的文件进行 cold archival
  • 写入新 fact 前通过 BM25 similarity 增加 conflict detection
  • 增加 category subdirectory(facts/<category>/)以及 memory_search category filter
  • 增加 token tracking(AuditEntry 中的 tokens 字段)
  • 增加手动触发 consolidation 的 mem_consolidate tool
  • memory_search corpus=all 增加 corpus supplement registration
  • 增加 EmbeddingConfig(None/OpenAI/Ollama),支持 TOML parsing 和 env override
  • memory_search signature 增加可选的 modecategory 参数
  • memory_search query 限制为 1024 个字符,防止 FTS5 resource exhaustion
  • 将 embedding error response body 截断到 200 个字符,防止 API key 泄漏
  • ConsolidatedFact 中区分 CJK 与 ASCII token estimation
  • 在 mutex 下持有 FactWriter JSONL file handle,防止 line interleaving
  • 通过 canonicalize + starts_with traversal guard,从 db path 推导 BM25Store mount root
  • 根据 entry timestamp 而非 chain length 计算 Episode duration
  • session_id 传播到提取的 episodic fact
  • consolidate() 返回 fact count,供 mem_consolidate reporting 使用
  • 修复 search response 中的 effectiveMode,使其反映实际使用的 mode
  • 修复 embedding API empty-response handling,返回维度正确的 zero vector

0.1.0

  • 引入面向 AI Agent 的 filesystem memory MCP server(仅 Linux),通过 stdio JSON-RPC 2.0 提供三个 tier 的 21 个 tool(Tier A file op、Tier B BM25 search、Tier C governance)
  • ~/.anolisa/memory/<ns>/ 下增加 per-namespace mount,并支持可选的 user namespace + private tmpfs isolation(auto/userland/userns strategy)
  • 对每次 Tier A file open 使用 openat2(RESOLVE_BENEATH | RESOLVE_NO_SYMLINKS) 强制执行 path sandbox
  • 增加带 transactional upsert、schema migration、trigram CJK tokenizer 和 inotify-driven debounced flush 的 SQLite FTS5 BM25 background index
  • 增加可选的 git versioning,auto-commit 在 per-handle mutex 下串行执行
  • 增加 tar.gz snapshot,使用严格的 id whitelist、restore 时的 atomic rename swap,以及 .anolisa/trash/ 下的 rollback entry
  • 增加可选的 cgroup v2 memory.max self-limit,在 tokio runtime 启动前应用
  • 增加 JSONL audit log(O_NOFOLLOW | O_CLOEXECMutex<File>),并支持可选的 systemd-journald fan-out
  • tools/listtools/call 强制执行 profile gating(basic/advanced/expert),config struct 使用 deny_unknown_fields
  • /run/anolisa/sessions/<sid>/ 下增加 per-session scratch 和 log(0700),并附带 tmpfiles.d snippet
  • 增加经过加固的 systemd user template anolisa-memory@.serviceProtectKernelTunables/Modules/LogsSystemCallFilterMemoryDenyWriteExecuteRestrictNamespacesRestrictAddressFamilies=AF_UNIX
  • 增加使用 offline vendor tarball 和单个 statically-linked binary(bundled SQLite + vendored libgit2)的 RPM packaging
  • 增加 OpenClaw plugin memory-anolisa,支持 install/detect/uninstall lifecycle,并提供 4 个通过 stdio child 路由到 MCP server 的 memory contract tool
  • 增加从 Cargo.toml 到 manifest/package/openclaw/mcp JSON 和 bundle 的 single-source version sync
  • 增加 mcp-harness example,以及覆盖 12 个 integration suite 的 140 个 automated test

Changelog

0.10.0

Agent Hook Policy Controls

  • Added code scanner enable flags for agent hooks. (#2001)
  • Unified hook policy controls across agent integrations. (#2141)
  • Added an observability hook environment toggle. (#2199)
  • Restored scanner mode environment variable names. (#2212)
  • Aligned code scanner hook flags across supported agent integrations. (#2229)
  • Added environment-based prompt scanner gating. (#2239)

OpenClaw Hook Integration

  • Added block mode support for the OpenClaw code scanner hook. (#2242)

Prompt Scanner

  • Widened prompt scan inbound text field coverage. (#2277)

Skill Ledger Runtime

  • Added read-only skill analysis. (#2044)
  • Included raw skill directories in skill ledger checks. (#2201)
  • Authenticated manifests before loading skill package contents. (#2185)

Security Events & CLI

  • Added session and run filters to agent-sec-cli events queries. (#2132)

Raw Packaging

  • Added component-owned raw package build targets and archive validation. (#2133)
  • Updated raw hooks to use the bundled Python launcher. (#2255)

0.9.0

Qoder CLI & Qwen Code Hook Capability Expansion

  • Added Qwen plugin and observability hooks. (#1473)
  • Added Qoder CLI hook framework support. (#1480)
  • Added Qoder prompt injection scanner hook integration. (#1529)
  • Added Qwen prompt scanner hook integration. (#1538)
  • Added code scanner hook integration for Qoder CLI and Qwen Code. (#1535)
  • Added Qoder CLI Skill PreToolUse skill ledger checks for user and project skills. (#1552)
  • Added Qwen PII hooks. (#1559)
  • Added Qwen skill ledger hook integration. (#1561)
  • Added Qoder CLI observability hook integration. (#1580)
  • Unified Qwen Code hook trace context handling. (#1738)

Codex & OpenClaw Hook Integrations

  • Added observability capability in the Codex plugin. (#1495)
  • Added Codex PreToolUse PII checker hook integration. (#1501)
  • Showed OpenClaw policy hints in hook responses. (#1525)

Scanner & Policy Engine

  • Skipped prompt model downloads when the model cache already exists. (#1467)
  • Added custom PII regex rules. (#1522)
  • Satisfied L1-L3 telemetry requirements. (#1527)
  • Added Chinese prompt-injection and jailbreak rules covering instruction override, authority escalation, encoding evasion, and role-play framing. (#1554)
  • Unified model resources into handles to make prompt scanning resource lifecycle more consistent. (#1553)
  • Made prompt scan mode configurable through environment variables. (#1620)
  • Hardened audit, PII, and notify hook behavior. (#1649)

Skill Ledger Runtime

  • Isolated the skill ledger worker for more reliable hook execution. (#1492)
  • Resolved canonical skill roots for skill ledger checks. (#1558)
  • Exposed skill ledger verdicts to hook callers. (#1577)

Build & Packaging

  • Moved prompt-scan benchmarks to a standalone repository to keep the CLI package lean. (#1557)
  • Rejected stale CLI wheels during packaging and runtime validation. (#1651)
  • Replaced and restarted the daemon service when upgrading RPM packages. (#1681)

Testing & CI

  • Fixed OpenClaw E2E test dependencies by excluding ML packages. (#1631)
  • Fixed skill-ledger E2E test execution on macOS. (#1643)

Documentation

  • Centralized user guides and added documentation lint CI. (#1586)

0.8.0

Build & Packaging

  • Installed the Codex plugin during source builds so source deployments include the same Codex integration as packaged installs. (#1302)
  • Updated source build scripts for the sec-core install flow. (#1348)
  • Fixed system-mode source builds by placing uv-managed Python under the shared sec-core library directory and adding a system install smoke check. (#1400)

Code Scanner

  • Added sensitive file path rules for common agent credentials to block API key exposure. (#1401)

OpenClaw Plugin

  • Hardened OpenClaw deploy compatibility handling and covered deployment edge cases with unit tests. (#1358)
  • Added an OpenClaw plugin cross-version E2E matrix that validates packaged plugin loading, Gateway flows, policy behavior, and observability across supported OpenClaw hosts. (#1372)

Documentation

  • Added bilingual agent-sec-core user guide documentation and documentation maintenance rules. (#1311)
  • Documented OpenClaw plugin deployment, compatibility, and upgrade guidance. (#1370)

0.7.1

Prompt Scanner

  • Degraded scan-prompt to fast mode when model unready; rewrote DENY to WARN and enriched degraded reason with diagnostics. (#1258)

Skill Ledger

  • Clarified skill ledger fallback warnings and sanitized finding summaries. (#1240)
  • Tamed ledger reconcile noise and typed live-root skip errors. (#1232)

Security Observability

  • Added observability mapping for new pii_scan at before_tool_call & after_tool_call. (#1229)

0.7.0

Codex Plugin — Full security integration for OpenAI Codex

  • Added codex-plugin with code scanning, prompt scanning, skill ledger, and PII checking hooks. (#1074)
  • Supported packaging codex-plugin into RPM. (#1138)
  • Fixed codex-plugin paths in Makefile and CI for correct RPM install verification. (#1165)

Code Scanner

  • Added code-scanner LLM mode for AI-assisted security analysis. (#1108)
  • Added code-scanner static rules for expanded coverage. (#1033)

Prompt Scanner

  • Added L4 multi-turn intent detection with ollama model service. (#1060)
  • Routed prompt scan to daemon and added prompt model preload for reduced latency. (#786)
  • Controlled prompt scan call to use daemon by env variable. (#933)

Skill Ledger — Activation daemon and policy engine

  • Added Skill Ledger activation daemon for background integrity monitoring. (#857)
  • Added runtime activation resolver for skill trust decisions. (#826)
  • Added skill ledger activation policy for configurable enforcement. (#944)
  • Updated skill ledger activation and event contracts. (#983)
  • Updated Skill Ledger hook defaults and reconcile notify behavior. (#1086)
  • Aligned skill ledger hooks across all agent platforms. (#1135)
  • Resolved Skill Ledger FUSE and unmanaged roots handling. (#1141)
  • Fail-open unsupported Hermes skill ledger scenarios. (#1155)

Daemon & Telemetry

  • Added daemon service with systemd integration and RPM build support. (#1090)
  • Exposed SQL query endpoint at daemon for observability queries. (#1042)
  • Enhanced daemon logging including requests and jobs. (#871)
  • Added telemetry schema definition and SLS JSONL writer. (#977, #1008)
  • Passed agent_name to telemetry data for multi-agent identification. (#1032)
  • Added logging system for structured agent-sec-cli output. (#651)
  • Added security daemon socket fallback under /run/user/<uid> for user-scoped deployments. (#1129)

PII Scanner

  • Extended PII scanning coverage with additional pattern detectors. (#925)

Security Observability

  • Added session report command for post-session security summaries. (#703)

Sandbox

  • Converged sandbox trigger rules for consistent enforcement. (#979)

Adapter & Build

  • Added ANOLISA CLI component.toml for adapter manifest integration. (#1067)
  • Added systemd-rpm-macros as RPM build dependency. (#1156)

0.6.0

Self-Protection — Tamper-resistance for agent-sec-core itself

  • Added self-protect code-scan rules that block disabling/uninstalling agent-sec plugins on OpenClaw and Hermes. (#692)
  • Optimized self-protect rules in code-scan to eliminate false positives on prefix-matched plugin names and cover Hermes uninstall/rm patterns. (#710)

Prompt Scanner

  • Unified prompt-scan warning format across cosh-extension, hermes-plugin, and openclaw-plugin with structured fields (threat type, risk level, interception stage, model confidence). (#709)

Agent-Sec-CLI

  • Added daemon process for agent-sec-cli to amortize startup latency across hook invocations. (#677)

Adapter & Manifest

  • Added standalone ANOLISA adapter entry anolisa-for-openclaw to package sec-core OpenClaw adapter scripts and drive install/detect/uninstall via the adapter manifest. (#549)
  • Added Hermes adapter runner: refactored the OpenClaw entry into a target-agnostic anolisa-adapter-runner and added anolisa-for-hermes wrapper, with per-agent adapter directory layout under sec-core. (#617)
  • Centralized sec-core adapter manifest parsing across adapter scripts and moved the manifest under the cli package. (#617)

OpenClaw Integration

  • Normalized OpenClaw state directory handling: use OPENCLAW_STATE_DIR for adapter filesystem state, unset OPENCLAW_HOME when invoking the OpenClaw CLI, and aligned plugin install/list/uninstall handling. (#641)

0.5.0

PII Scanner — Personal information leak detection

  • Added PIIChecker scan CLI with text/file input, regex/validator-based detection, redaction, and security middleware integration. (#525)
  • Added PIIChecker hooks for cosh and OpenClaw with stdin-based input passing. (#539)
  • Added Hermes PII checker hook. (#556)
  • Fixed scan-pii module mode detection via subprocess. (#540)

Security Observability — Agent run metrics & posture insights

  • Added security observability schema, metrics definition, and CLI with jsonl writer for agent runs. (#488)
  • Added openclaw plugin for security observability. (#515)
  • Added cosh hook for security observability. (#528)
  • Persisted observability records to sqldb with CLI review command. (#544)
  • Added observability plugin for hermes. (#553)
  • Correlated security events with observability events and supported batch query. (#578)
  • Respected trace-id filter in count queries. (#595)

Hermes Plugin — AI Agent integration framework

  • Added hermes-plugin framework with abstract hook class and code scan capability. (#536)
  • Added Hermes prompt-scan capability. (#579)
  • Added Hermes PII checker hook. (#556)
  • Added Hermes skill ledger hook. (#565)
  • Added observability plugin for hermes. (#553)
  • Supported correlation context in hermes agent plugin. (#590)
  • Added hermes plugin install for rpmbuild and build from scratch. (#577)
  • Stabilized Hermes skill-ledger warning delivery for non-pass skill checks. (#600)

Correlation & Tracing Context

  • Unified caller tracing context across CLI, OpenClaw, and cosh with --trace-context JSON and SQLite schema v2. (#569)
  • Supported correlation context in hermes agent plugin. (#590)
  • Correlated security events with observability events. (#578)

Skill Ledger

  • Integrated code-scanner with skill-ledger for unified security assessment. (#505)
  • Updated skill ledger security interactions. (#529)
  • Made openclaw skill ledger approval configurable. (#575)
  • Added Hermes skill ledger hook. (#565)
  • Refined skill ledger scan workflow and aligned documentation. (#529)
  • Included skill-ledger e2e in install flows. (#573)
  • Fixed skill-ledger hook scope limitation. (#497)
  • Fixed managed skill dirs for discovery. (#510)
  • Expanded home paths for skill-ledger. (#596)
  • Hardened skill ledger recovery and key UX. (#575)

Code Scanner

  • Added code-scan requireApproval config for openclaw. (#560)
  • Added OpenClaw enableBlock hook policies. (#586)

Security Middleware & Event System

  • Fixed TOCTOU race condition at sqldb read path. (#546)
  • Made SQLAlchemy lazy import for non-DB subcommands. (#581)
  • Lowered frequency for SQL maintenance operations. (#546)

Prompt Scanner

  • Added Hermes prompt-scan capability via hermes plugin. (#579)
  • Fixed warmup detection from error-string matching to file-based check. (#500)
  • Fixed prompt text passing via stdin instead of argv. (#579)

Toolchain & CI

  • Added build-all support with local space install for sec-core. (#527)
  • Added hermes plugin install for rpmbuild and from-scratch build. (#577)
  • Included skill-ledger e2e in install flows. (#573)
  • Added adapter manifest for capability discovery. (#577)

0.4.0

Prompt Scanner

  • Prompt scanner hook now asks user on missing model instead of fail-open. (#463)
  • Added prompt injection detection benchmark dataset and evaluation toolkit. (#464)

Security Middleware & Event System

  • Refactored security_events SQLite storage to SQLAlchemy ORM with multi-table extensibility and typed repositories. (#459)

Skill Ledger

  • Fixed sign-skill auto-register config (exact awk match) and parse openclaw stdout unconditionally. (#445)
  • Unified XDG paths under agent-sec/skill-ledger vendor namespace. (#445)
  • Unified single-skill verify into structured result for consistent output. (#445)
  • Converted integration tests from subprocess to Typer CliRunner. (#445)

OpenClaw Integration

  • Registered plugin at openclaw gateway explicitly to support Gateway startup planning. (#446)

Refactoring

  • Removed deprecated agent-sec-core skill directory; aligned README and spec with agent-sec-cli workflow. (#454)

Toolchain & CI

  • Added coverage report for sec-core CI. (#431)
  • Enabled rpmbuild and e2e test CI for main branch. (#432)

0.3.0

Prompt Scanner — Multi-layer prompt injection & jailbreak detection

  • Added prompt injection/jailbreak detection scanner architecture with L1 rule engine (YAML-based) and L2 ML classifier (Prompt Guard 2). (#253)
  • Integrated prompt scanner into cosh hook and openclaw plugin with security middleware lifecycle. (#261, #294)
  • Added list-scanners command, improved CLI help, and made --scanner-version optional. (#284)
  • Added prompt scan summary and backend tests. (#294)
  • Added prompt-scanner skill definition. (#256)
  • Added model warmup, audit logging, and comprehensive documentation. (#253)
  • Stabilized batch scanning and verdict logic with thread-safe model loading. (#253)
  • Unified prompt scanner response to use "ask" instead of "block". (#341)
  • Added prompt-scanner e2e test suite and Makefile target. (#352)

Code Scanner — Static code security analysis

  • Added code scanner component with rule-based detection for obfuscation, permission abuse, and more. (#234)
  • Integrated code scanner into cosh hook (with ask decision support) and openclaw plugin adapter. (#234)
  • Added code scanner CLI entry, error codes, and unit tests. (#234)
  • Fixed code scan bugs and added e2e test. (#342)

Skill Ledger — Skill integrity tracking and signing

  • Added skill-ledger CLI with middleware integration for skill integrity verification. (#252)
  • Added skill-ledger skill definition. (#266)
  • Added skill-ledger cosh hook for PreToolUse and openclaw-plugin capability. (#292, #281)
  • Improved skill-ledger CLI and cleaned up imports. (#284)
  • Restructured skill-ledger config defaults and documentation. (#296)
  • Aligned skill-ledger tool name and added path validation. (#317)
  • Reworked skill-ledger status, output, and check signing. (#335)
  • Skill-ledger hook hardening, e2e suite, and posture integration. (#339)
  • Known limitation: skill directory resolution assumes dir name matches SKILL.md name field; see #381.

Security Middleware & Event System

  • Added security middleware framework with unified CLI entry point and metrics integration. (#121, #220)
  • Added sqldb writer & reader with query command at CLI interface for security event persistence. (#254)
  • Fixed cross-process event loss in SecurityEventWriter. (#226)
  • Applied corruption whitelist to stop false-positive DB rebuilds. (#338)
  • Added e2e test and fixed bugs revealed during testing. (#330)

Linux Sandbox

  • Added sandbox guard and failure handler hooks. (#362)

OpenClaw Integration

  • Added hook plugin for openclaw with integrated security scanning capabilities. (#242)
  • Added jq requires for openclaw hook package. (#370)

Cosh Extension Integration

  • Integrated with new cosh extension API and added builtin commands. (#302)

Performance

  • Lazy-load ML dependencies to speed up non-ML subcommands. (#318)

Toolchain & CI

  • Migrated Python toolchain to uv package manager and pinned Python 3.11.6. (#227)
  • Added sec-core RPM build CI and adapted nightly build pipeline. (#295)
  • Initialized code format check CI with python-code-pretty. (#229)
  • Added e2e test in RPM build CI. (#369)

Bug Fixes

  • Preserved seharden wrapper defaults. (#236)
  • Removed dynamic import at middleware router. (#277)
  • Improved missing loongshield guidance. (#289)
  • Fixed build errors. (#288)
  • Removed openclaw hook examples and fixed documentation. (#282)

0.2.0

  • Added Hardened skill signing pipeline and added .skill-meta layout. (#129)
  • Added Cargo.lock to version control. (#149)
  • Added make install-sandbox target. (#68)
  • Fixed bubblewrap version compatibility for --argv0 option. (#112)
  • Changed Refactor SKILL.md to executable protocol and align sub-skills. (#130)

Changelog

0.9.1

Features

  • Add case containment lifecycle with policy handoff, no-gap replacement, dedicated API, and dashboard views.
  • Add system audit protocol, event storage, dashboard, and extract audit service into a dedicated crate.
  • Add ActPlane risk enforcement with enforcer service, hardened file controls, secure lifecycle, and risk enforcement dashboard.
  • Rework optimization dashboard views and add detour-based cost waste analysis.
  • Move agent health and interruptions to a dedicated dashboard page.

Fixes

  • Extract cache tokens for OpenAI (prompt_tokens_details.cached_tokens) and DashScope (top-level cached_tokens) responses, and extract real user query from cosh-ng adapter prompt template.
  • Capture Claude Code launched via absolute path or node wrapper.
  • Skip agent_crash detection on clean exit and flush deferred GenAI events on agent exit.
  • Skip message parse for non-LLM paths.
  • Encrypt optimization config API key.
  • Show known agent rules.
  • Map cosh session temporary file writes. (#2080)

CI

  • Pin eBPF build to clang 15 and use dedicated runner pools.

0.9.0

Features

  • Add optimization analysis workspace, APIs, persistent analysis history, and dashboard pages for accuracy, performance, and cost reviews.
  • Add Qoder trajectory collection, ATIF v1.7 export, batch analysis tooling, and subagent trajectory navigation with topology-style views.
  • Add command-line discovery rules for CoshNG and normalize LLM event attribution with command-line context.
  • Add six new interruption types and fallback capture for unparsable LLM HTTPS traffic.

Fixes

  • Fix Anthropic SSE parsing, system prompt injection, and cache token accounting.
  • Fix ATIF batch output to use the shared ATIF v1.7 schema and drop stale v1.6 paths.
  • Fix optimization and trajectory collection edge cases, including stale conversation anchors and syscall tracepoint probe attach.
  • Fix dashboard empty states, error banner wording, auth loopback handling, and session navigation behavior.
  • Make raw HTTPS FFI output opt-in and skip duplicate SSE message parsing for OpenAI and Anthropic streams.

Changed

  • Group optimization dimension analyses under per-target run roots and represent parallel LLM calls as ATIF subagent trajectories.
  • Slim and gate default SLS output so trace content is not uploaded unless explicitly enabled.

0.8.1

Fixes

  • Replace lock().unwrap() with poison-safe unwrap_or_else for mutex recovery.
  • Correct SSL library attribution from aws-lc/BoringSSL to OpenSSL 3.x.
  • Add Claude process name to BoringSSL classification.
  • Preserve user config on schema migration instead of overwriting.
  • Don't auto-overwrite invalid JSON configs; record process pid not thread tid in ns pid helper.
  • Downgrade high-frequency event logs from debug to trace to reduce noise.

Tests

  • Expand unit tests for handlers, interruption store, and token store.
  • Add poison-recovery tests for mutex unwrap_or_else changes.

0.8.0

Features

  • Add dashboard token-based authentication with file-only auth config.
  • Add LAN/public IP address display and Chinese output in dashboard CLI.
  • Add ECS security group guide and metadata integration to dashboard.
  • Add conversation grader API and dashboard controls.
  • Add COSH_SESSION_ID export for per-run session correlation.
  • Auto-upgrade stale configs via schema_version.

Fixes

  • Fix Codex SSL capture and SSE token extraction.
  • Fix false interruption signals.
  • Persist idle streams and tool results to avoid snapshot loss.
  • Detect SSE stream errors explicitly.
  • Restrict /health, /metrics, and server auth to localhost/file-only config.
  • Remove hf-hub git fork from default build dependency.
  • Fix IMDSv2 token fetching, probe deadlines, and ECS metadata deduplication.
  • Fix RPM build to copy agentsight.json into source tarball.
  • Address clippy single_match, nested if-let, and architecture boundary issues.

Tests

  • Add dashboard mock HTTP and unit tests for coverage gate.
  • Add build_output and public_address tests.
  • Mark probe tests as #[ignore] for CI ECS runners.

0.7.1

Fixes

  • Improve severity labels and agent sidebar UX.
  • Show all verdicts in the summary command.
  • Sync component.toml version with package version.

0.7.0

Features

  • Add Codex CLI adaptation with three-tier SSL probe attach (symbol table → byte pattern → offset table) and cross-chunk SSE continuation buffer.
  • Add security observability dashboard and server proxy for agent threat visibility.
  • Add memory optimization with bounded event buffers, feature flags (features.*) and configurable runtime limits (runtime_limits.*).
  • Add container_id to AgentsightLLMData for container-level attribution.
  • Derive session_id from process environment variables and request metadata instead of message content.
  • Add call_kind classification (chat / completion / embedding / tool_use) to GenAI semantic events.
  • Add --exclude filter to agentsight audit CLI for noise reduction, and show non-streaming LLM calls in audit output.
  • Add unified agentsight summary command for one-shot status overview.
  • Enhance token savings page with baseline comparison, strategy breakdown, line-level diff highlighting and optimization tips.
  • Upload skill metrics via SLS Logtail exporter.
  • Improve agent health UX: role badges (P1/P2), TTL-based cleanup, process-ancestry grouping, and Session ID help tooltip.
  • Filter client processes from health API to reduce dashboard noise.
  • Add anolisa component contract for RPM lifecycle integration.

Fixes

  • Fix sslsniff BPF verifier rejection on kernel 5.15 and add BPF load tests.
  • Fix traced_processes BPF map leak causing uprobe attach failure after long runtime.
  • Prevent duplicate uprobe Links by retaining inodes in traced_files on detach.
  • Decode compressed (zstd/brotli) SSE streams so Claude Code and similar agents are fully captured.
  • Harden compressed SSE decode against partial chunk boundaries.
  • Extract token usage from non-streaming and HTTP/2 responses.
  • Fix namespace PID usage in udpdns and tcpsniff probes.
  • Strip /proc/{pid}/root prefix for uprobe attach in containerized environments.
  • Implement tiered SSL and tcpsniff ring buffer reservations to reduce dropped events.
  • Clamp before mask in filewrite/udpdns BPF probes; cap stdout payload to MAX-1.
  • Change cgroup gate to OR semantics and add trace_cgroup FFI interface.
  • Tighten SSE truncation detection and write pending row for deferred GenAI calls.
  • Respect dynamic sysom path in SLS exporter mode selection; replace removed sysom_logtail_path with logtail_path filter.
  • Validate ring buffer size is power-of-two at startup.
  • Wire feature flags and runtime limits to actual runtime code paths.

Refactoring

  • Split genai/builder.rs into 4 focused modules and genai.rs into 5 submodules.
  • Bundle shared BPF maps into SharedMaps for reduced duplication.
  • Extract background threads module with stop-signal support.
  • Replace remaining unwrap() calls with if-let / ? patterns.

CI & Quality

  • Add fmt, clippy, unit test coverage, and architecture boundary check CI gates.
  • Add clippy.toml + cargo-deny for lint and supply-chain auditing.
  • Add architecture boundary check script (check-arch-boundary.py).
  • Add scoped AGENTS.md for FFI, unified orchestrator, and storage modules.
  • Define Footprint Ladder for code surface growth control.
  • Add agentsight-code-review and pr-body develop-skills.

0.6.1

  • Add real-time agent_crash detection in trace mode.
  • Add OOM crash detection.
  • Add cgroup-level event filtering with v1/v2 compatibility.
  • Support QwenCode skill discovery via per-user home scanning.
  • Support SLS Logtail activation reversible via dynamic path.
  • Support bridging ilogtail SLS_LOG_PATH into config via token-collector switch.
  • Default traceEnabled to false to drop conversation content from SLS by default.
  • Drop gen_ai.system_instructions from SLS uploads when traceEnabled=false.
  • Refactor session_id and conversation_id derivation from response_id instead of message content.
  • Fix CJK deadloop detection, kill() error check, and SIGKILL escalation.
  • Fix SQLite read/write contention via VACUUM optimization.
  • Fix rpm-build.sh agentsight build failures.
  • Fix allow log path re-init on repeated new+start.

0.6.0

  • Add deadloop detection and auto-kill mechanism for runaway agent processes.
  • Add retry storm detection and /metrics interruption counters.
  • Add BPF-layer HTTP protocol filter and wildcard capture (*) for unknown IP/port targets.
  • Add client-side hybrid encryption for sensitive message fields.
  • Add traceEnabled configuration toggle with SLS upload layer enforcement.
  • Add HTTP domain rules resolved to tcpsniff BPF map via DNS.
  • Add default DashScope HTTPS rule and anolisa_release module.
  • Add FFI interface for tcp_targets and input_delta config.
  • Add CO-RE compatibility to UDP DNS probe for kernel 6.0+.
  • Support runtime SLS logtail path via config hot-reload.
  • Expand interruption types and add logtail export.
  • Restructure config to https/http rules.
  • Refactor query stats.db by tool_use_id and unify savings display.
  • Refactor load encryption public key from agentsight.json.
  • Fix decode HPACK Huffman headers.
  • Fix BoringSSL probe attachment, FFI event delivery, and chunked-body panic.
  • Fix preserve initial SSE chunk in event-stream responses.
  • Fix c_char / BPF comm portability (i8 vs u8).
  • Remove dead code and deprecated APIs.

0.5.0

  • Add Claude Code support including SSL probe attach for BoringSSL, Anthropic SSE thinking/tool_use content blocks, and message.id-based session correlation.
  • Add tcpsniff probe for plain HTTP traffic capture with configurable IP/port filtering (disabled by default with empty tcp_targets).
  • Add User-Agent based agent detection with comm fallback for simplified agent matching.
  • Add UDP DNS probe for agent discovery (replacing TLS SNI probe) with QNAME parsing moved to userspace.
  • Add TLS SNI probe module and refactor discovery to config-driven rules.
  • Add connection scanner for pre-established LLM API connections.
  • Add tools field to AgentsightLLMData FFI struct, passed through as raw JSON.
  • Add container PID namespace support in BPF traced process filtering and event emission.
  • Add agent matching rules and reduce BPF ring buffer to 32MB.
  • Add uid field to SLS logs with OnceLock cache and startup validation.
  • Support profile-based installs.
  • Fix duration_ns calculation in LLM data.
  • Fix SSL probe cleanup of stale inodes on process exit.
  • Fix BPF verifier -E2BIG issues by removing nested #pragma unroll in udpdns.bpf.c and masking payload_len on older kernels.
  • Fix skill extraction for Hermes agent architecture.
  • Fix Node.js process.title change handling in OpenClaw matcher.

0.4.0

  • Add HTTP/1.1 request body reassembly for fragmented SSL writes.
  • Add skill metrics analysis with cosh filesystem-based discovery.
  • Add SLS upload and Logtail file exporter for GenAI events.
  • Add hermes agent matcher for LLM process discovery.
  • Detect uv Python static OpenSSL in SSL sniffer.
  • Remove AK/SK-based SLS direct upload, keep Logtail file export.

0.3.1

  • Fix simplify agent_crash detection and fix multi-process dedup. (#411)
  • Fix use SqliteConfig for audit CLI db path. (#399)
  • Fix hide Cosh from agent health UI and remove keepalive support. (#401)
  • Fix API endpoint table in AGENTS.md. (#397)

0.3.0

  • Add interruption detection system with drain mechanism and dashboard integration. (#315)
  • Add token savings page and API endpoint for optimization visualization. (#310)
  • Add compounded token savings and request count tracking. (#320)
  • Add C FFI API with cbindgen header generation. (#306)
  • Add filewatch and filewrite eBPF probes for file access monitoring. (#308, #309)
  • Support SysOM AK/SK GenAI capture for cosh. (#305)
  • Use LLM API response_id as trace_id and add conversation_id field. (#304)
  • Resolve session_id from agent's own session via ResponseSessionMapper. (#303)
  • Fix interruption CLI and align conversation_id naming. (#318)
  • Fix cosh session_id recognition by supporting snake_case response_id. (#307)
  • Fix wrong tool call id in token savings compounding. (#316, #317)
  • Fix standardize call_id, add tool_call_ids column. (#319)
  • Fix session_id and response_id mapping in genai builder and storage. (#321)
  • Fix token savings display in conversation list. (#322)
  • Fix cache agent name by pid for dead process resolution. (#358)
  • Fix remove custom db path and use default paths. (#359)
  • Support nightly docker image build in CI. (#302)

0.2.2

  • Support starting backend-server for dashboard with AgentSight service.
  • Fix dashboard frontend dynamic width for multiple display-size.

0.2.1

  • Add /usr/lib/copilot-shell path to CoshMatcher for agent discovery. (#190)
  • Add 200MB size limit for genai_events.db to prevent unbounded growth. (#211)
  • Remove /api/stats endpoint returning incorrect data. (#197)
  • Extract audit from HttpRecord and filter non-LLM calls. (#196)
  • Always show comparison data when --compare flag is used in token queries. (#194)
  • Fix incorrect discover command in README documentation. (#191)
  • Remove breakdown command and keep token consumption commented. (#193)
  • Replace deprecated MemoryLimit with MemoryMax in systemd service file. (#181)

0.2.0

  • AgentSight Dashboard web UI with real-time monitoring interface. (#74)
  • Agent health monitoring with offline alerting and hung process dashboard restart. (#158)
  • One-click navigation from dashboard to ATIF trace analysis page. (#116)
  • /metrics endpoint to expose standard Prometheus-format data. (#134)
  • Support for HTTP 2.0 protocol. (#147)
  • Support to build RPM package. (#166)

变更日志

本文件记录 ANOLISA 的所有重要变更。

格式基于 Keep a Changelog, 版本号遵循 语义化版本

[未发布]

[0.2.19] - 2026-08-10

修复

  • 在 Raw 安装准备系统依赖时,现会将 resolver 提供的 rpmdeb package-family hint 直接映射到相应的 package manager backend。在缺少可选 which command 的最小化受支持主机上,不再仅因此报告不支持 package base, 同时保持对 distro-specific hint 的兼容 (#2314)。
  • anolisa --json osbase sandbox listanolisa --json register status 现使用标准 success envelope,包含 okschema_versioncommand metadata,并将业务字段嵌套在 data 下。脚本现可 与其他 JSON surface 一致地解析这些 legacy command (#2319)。
  • OpenClaw adapter 现以 OpenClaw 兼容的 whitespace、tilde 和 absolute-path 处理方式遵循 OPENCLAW_STATE_DIR,使 plugin、skill、receipt、status 和 disable 操作都使用配置的 state。Re-enable 会安全迁移 legacy fallback 下记录的 resource,在 cleanup 需重试时保留旧 receipt,并在 --dry-run 中预览迁移。若旧 receipt 使用的 OPENCLAW_HOME 当前已不在 environment 中,迁移或 cleanup 前需 临时恢复该变量 (#2337)。

[0.2.18] - 2026-08-06

变更

  • Telemetry 上传现将 SLS_PROJECT_PREFIX 视为 SLS project prefix,并附加 检测到的 region,例如 anolisa-cn-hangzhou。设置旧 SLS_PROJECT 的部署 必须迁移至 SLS_PROJECT_PREFIX,以便将数据上传到相应 region 的 project (#2260)。

修复

  • Raw 安装现仅将选中的 archive payload 通过私有、disk-backed staging 流式 处理,不再将解压后的内容保留在内存中。大型 package 可以使用有界的 payload 内存完成安装,同时保留 atomic placement、rollback、cleanup 和 digest verification (#2250)。
  • anolisa statusanolisa doctor 现会 hash 最大 2 GiB 的 ANOLISA-owned file,并将更大的 file 视为未检查和 degraded,而不是 failed。包含大型 artifact 的完整组件不再显示为损坏或触发多余的 repair,同时在必须完成 verification 的 recovery 场景中仍会 fail closed (#2271)。
  • Enable 声明了 hook 的 Codex adapter 时,现会发现已安装 plugin 的 hook identity,并以 atomic 方式持久化其 trusted hash,使 non-interactive codex exec session 可以运行这些 hook。缺失 hook 或被覆盖的 trust setting 会以可操作的诊断信息中止 enable (#2281)。

[0.2.17] - 2026-08-05

新增

  • Raw 安装现可在放置声明的文本文件前渲染其中的 {bindir}{datadir} 等 layout placeholder,使共享的软件包模板遵循所选安装 scope 与 prefix。 完整性检查和 repair 使用渲染后的字节 (#2222)。

变更

  • Raw repository 解析现会在已发布时优先使用第二代 index,并强制检查各组件的 CLI 最低版本。不兼容的条目会给出 anolisa update self 提示并失败,而不会 静默安装较旧或格式错误的结果,同时保持对第一代 repository 的兼容 (#2222)。
  • RPM-backed adapter 的 scan、status 和 enable 操作现使用声明的软件包自有 resource root;root 缺失或无效时会明确报告,而不会回退到过期的 raw 文件。 目标位于外部 RPM root 的 Codex adapter 会记录 trust anchor;降级到 0.2.16 前需先 disable 这些 adapter (#2222)。

修复

  • Qoder native plugin bundle 现使用 Qoder 自身的 plugin lifecycle,不再按 legacy hook bundle 复制或改写。User scope 和 project scope 中已有的同 ID plugin 会受到保护;无法确认的安装或移除会保留可重试的 receipt,而不会认领或 删除用户状态 (#2221)。

[0.2.16] - 2026-08-03

新增

  • 成功执行的 anolisa update <component>anolisa update all 现会报告 resource bundle 已变化的 adapter,并给出准确的 anolisa adapter enable ...anolisa adapter status ... 后续命令。JSON 响应通过稳定的 adapter_actions 数组提供同样的信息 (#2018)。

修复

  • 在同时缺少 RPM 工具和 RPM database 的 Debian 系发行版上,system scope raw 安装不再因 rpm not found on PATH 而失败。如果已有 RPM database, 或安装期间新出现 RPM database,仍会在任何文件变更前停止 raw 安装 (#2061)。

[0.2.15] - 2026-07-30

新增

  • 交互式 anolisa installanolisa install --allanolisa uninstall 现会在耗时的规划与执行阶段显示分阶段进度。支持 ANSI 的终端会动态显示当前阶段, 能力受限的交互式终端则输出静态阶段提示 (#2036)。

变更

  • 面向用户的失败信息现采用常规的 error:hint: 标签,不再显示机器错误码; --json 仍保留结构化错误码,退出状态保持不变。
  • 更新通知现会为建议运行的 sudo anolisa upgradeanolisa update --check 命令加上引号,使命令边界更加清晰。

[0.2.14] - 2026-07-29

修复

  • anolisa statusanolisa doctor 现可检测 raw 托管文件的 Unix mode 与 Linux file capability 漂移(包括由旧版本记录的安装),并建议运行 anolisa repair 进行恢复。
  • anolisa repair 现会在仅文件元数据漂移时重新部署 raw 托管组件,恢复声明的 mode 和已确认的 capability。更新失败后的回滚仅恢复操作前已确认生效的 capability,避免授予原安装中未成功应用的可选 capability (#1987)。

[0.2.13] - 2026-07-28

新增

  • @anolisa/cli npm 软件包现支持 macOS arm64,并在安装时选择匹配的原生二进制。
  • Tokenless adapter 现支持 Qwencode,同时保持 Cosh extension 与共享 hook 资源相互独立。

修复

  • raw 安装现拒绝 provision 被另一个 pending RPM 安装占用的系统软件包,并引导用户运行 anolisa repair,避免组件相互占用或在后续移除对方的依赖。
  • cosh-ng RPM 安装现保留 cosh-ng 组件身份。以 cosh 保存且可明确识别的旧记录和 recovery journal 会被修复,使 lifecycle 命令操作正确的组件。
  • raw 更新和修复失败后的回滚现会恢复文件权限和 capability,确保恢复的二进制仍可执行。
  • 启用 Tokenless Qoder adapter 时,现会解析缓存 plugin 中的共享 hook 路径,避免匹配的 tool call 因 hook 命令路径错误而失败。

[0.2.12] - 2026-07-27

变更

  • 对已安装组件执行操作的命令在目标缺失时现报告 NOT_INSTALLED,不再报告 INVALID_ARGUMENT,调用方无需解析错误消息即可区分“没有可操作的目标”和“调用方式错误”。 该错误码仅表示状态缺失,不表示组件名称是否有效;影响 uninstallupdaterepairforgetrestartadapter,退出码仍为 2 (#1915)。

修复

  • adapter 状态检查现忽略空的或不完整的过期源目录,并将缺失 bundle 报告为 degraded; raw 卸载会清理空目录,避免遮蔽其他安装 scope (#1850)。
  • raw 安装 dry-run 现会在执行前校验组件冲突,使预览结果与实际安装保持一致。仓库缺少 轻量 sidecar 元数据时会提示已跳过冲突校验 (#1898)。

[0.2.11] - 2026-07-24

新增

  • raw anolisa install --version 现可安装指定的已发布组件版本。
  • raw anolisa install --version 输出现显示请求版本、解析版本、制品地址和来源。

变更

  • 请求的 raw 版本不可用时,anolisa install --version 现列出已发布版本。

修复

  • 请求的 raw 版本不可用时,anolisa install --version 不再安装其他版本。
  • 包含大量文件的 raw 组件卸载速度更快,写入量显著降低。
  • 操作恢复数据缺失或损坏时,恢复流程现会保留已安装状态。

[0.2.10] - 2026-07-23

新增

  • anolisa telemetry 现可启用或停用数据收集。
  • anolisa telemetry 现可关联或取消具名上报。
  • anolisa telemetry status 现以文本或 JSON 显示收集和具名上报状态。
  • adapter 启用和停用命令现显示组件提供的后续提示。
  • adapter JSON 输出现包含结构化组件提示。
  • anolisa install --version JSON 输出现包含请求版本、解析版本、来源及精确 RPM。

变更

  • 全新 ANOLISA RPM 安装现默认启用匿名遥测。
  • RPM 安装输出现说明如何停用遥测。
  • 已启用的遥测现会在支持的主机重启后自动恢复。
  • anolisa register 现提示该命令已弃用。
  • anolisa register 现无需确认即可启用遥测。
  • anolisa register status 现引导使用 anolisa telemetry status
  • anolisa unregister 现停用遥测并保留本地日志。
  • anolisa install --version 现精确选择与请求版本匹配且兼容本机的 RPM。
  • anolisa install --dry-run --version 现验证可用性并显示解析后的 RPM 详情。
  • adapter dry-run 现预览组件提示且不更改主机。
  • adapter quiet 输出现隐藏组件提示。

修复

  • anolisa register 现避免旧遥测配置重复上传。
  • anolisa unregister 不再让旧遥测配置继续上报。
  • anolisa install --version 在请求版本不可用或不兼容本机时不再更改主机。
  • anolisa install --version 安装到其他 RPM 版本时不再记录成功。
  • anolisa repair 现拒绝已装版本偏离原请求的中断 RPM 安装。
  • anolisa repair 现报告中断 RPM 安装的架构无法验证。
  • anolisa adapter disable 现可在组件文件不可用时显示已保存提示。
  • adapter 提示不再能向可读输出注入终端格式。

[0.2.9] - 2026-07-22

新增

  • anolisa update all 现更新全部已跟踪的 raw 与 RPM 组件,不更新 CLI。
  • anolisa repair 现可按记录版本恢复损坏的 raw 安装。
  • anolisa repair 现支持无 root 权限修复 user scope 安装。
  • anolisa repair 现可恢复中断的安装、更新、采纳、卸载和批量操作。
  • anolisa repair 现可重装缺失的托管 RPM 软件包。
  • anolisa status 现将不明旧记录标为需处理,并给出按 scope 修复或遗忘的指引。
  • anolisa statusanolisa doctor 现按安装时保存的组件清单执行健康检查。
  • user mode 的 adapter 命令现可作用于可见的 system 安装。
  • anolisa repair 现可根据已安装软件包或完好文件恢复不明旧记录。
  • anolisa forget 现可仅删除不明旧记录,不改动已安装内容。

变更

  • anolisa install 遇到未托管的 system RPM 时现会拒绝,并提示使用 anolisa adopt
  • 已跟踪组件再次执行 anolisa install 时现直接成功,不再重复安装。
  • anolisa adopt 现允许更新既有 RPM,卸载软件包仍需显式授权。
  • 已采纳软件包再次执行 anolisa adopt 时现直接成功。
  • 仅观察的 RPM 组件现须先执行 anolisa adopt 才能更新。
  • anolisa install --all 现用一次软件包事务安装全部新 RPM。
  • anolisa upgrade 现用一次软件包事务完成全部 RPM 更新。
  • anolisa upgrade 现用一次软件包事务安装全部计划内 RPM。
  • anolisa listanolisa status 现分别显示同名组件的 user 和 system 记录。
  • anolisa list 现将记录标为 owned、managed、adopted 或 observed。
  • anolisa --install-mode user install 现可在 system 安装旁创建独立 user 安装。
  • 生命周期修改现严格限制在所选 scope,软件包别名也不例外。
  • 首次修改旧状态时现自动升级格式,并保留 installed.toml.v4.bak
  • 遇到新版状态格式时现会报错,不再显示为空状态。
  • install-anolisa.sh 现由 CLI 获取分发索引,以使用镜像最新数据。
  • install-anolisa.sh 现仅部署 OS-base 清单,组件清单改为按需获取。
  • install-anolisa.sh --strict 现仅校验二进制和清单包。
  • ANOLISA_INDEX_URLANOLISA_INDEX_SHA256 现不再影响安装脚本。
  • 安装、采纳、更新、修复和卸载的 JSON 输出现包含明确执行计划。
  • raw 与 RPM 组件的卸载 JSON 现统一格式,并包含删除方式和计划。
  • anolisa uninstall --dry-run 遇到缺失组件时现会报错,不再返回空成功计划。
  • 组件存在待恢复操作时,anolisa forgetanolisa restart 现会停止。
  • anolisa doctor 现会报告没有活动组件记录的未完成操作。

修复

  • RPM 托管组件不再因 raw 安装健康检查被 statusdoctor 误报失败。
  • RPM 组件更新现会先刷新已保存组件清单,再报告成功。
  • RPM 清单刷新未完成时,anolisa logs --severity warn 现可检索该操作。
  • RPM 更新中断后现保持可修复,不再以过期设置显示成功。
  • anolisa doctor 遇到损坏或不明确的恢复数据时不再建议生命周期命令。
  • 多个组件共用状态目录时,anolisa doctor 不再重复报告恢复问题。
  • anolisa doctor --help 现明确说明 --fix 尚不可用。
  • 批量 RPM 操作失败后,已变更软件包现会保留可修复状态。
  • 组件别名不再将生命周期修改导向其他 scope 的安装。
  • 跨 scope 健康检查现使用正确的 user 服务管理器。
  • 批量 RPM 操作失败后,未受影响组件现会单独重试。

[0.2.8] - 2026-07-21

新增

  • anolisa adapter enable 现支持以 --allow-unsafe-plugin-install 显式授权 OpenClaw 不安全插件安装。
  • OpenClaw 适配器设置现可限定适用的 OpenClaw 版本。

变更

  • anolisa adapter enable 现会在执行任何更改前检查 OpenClaw 兼容性。
  • anolisa adapter enable 现会确认 OpenClaw 插件已加载后再报告成功。
  • OpenClaw 阻止不安全插件时,ANOLISA 现会显示检查结果。
  • OpenClaw 支持显式授权时,安全错误现会提示授权重试。

修复

  • OpenClaw 设置更新失败后,现可保留受影响设置供重试。
  • 重新启用 OpenClaw 适配器时,不再丢失此前已应用的设置记录。
  • anolisa adapter disable 现会提示更新结果不确定且可能残留的 OpenClaw 设置。

[0.2.7] - 2026-07-18

新增

  • anolisa adapter 现可通过 qwen CLI 管理 Qwen Code 0.17 及更高版本的扩展。

变更

  • anolisa upgradeanolisa repair 现会在人类可读和 JSON 输出中说明组件清单同步。

修复

  • anolisa upgrade 现会在 RPM 软件包升级后刷新组件清单。
  • anolisa upgrade 现可同步版本号未变的 RPM 组件清单变更。
  • anolisa repair 现会从已安装的 RPM 刷新过期组件清单。
  • 组件清单刷新失败时,现会保持 RPM 组件可修复并报告受影响组件。

[0.2.6] - 2026-07-16

修复

  • anolisa status 不再误报正常 RPM 组件失败。

[0.2.5] - 2026-07-14

新增

  • anolisa repair 现可恢复软件包安装后中断的首次 RPM 安装。
  • anolisa update --check 现会报告已保存状态需要同步的 RPM 组件。

变更

  • 安装、接管和升级命令现会先要求修复中断的 RPM 安装。

修复

  • 并发 RPM 安装现会安全失败,不再覆盖其他操作的组件状态。
  • 重装缺失的 ANOLISA 托管 RPM 时,现会保留组件设置和历史记录。
  • anolisa uninstall --dry-run --json 现包含 dry_run: true,且未安装组件不再显示删除阶段。
  • anolisa upgrade 现会在升级后刷新已保存的 RPM 版本和软件包信息。
  • anolisa upgrade 现可同步缺少软件包信息的旧版 RPM 记录。

[0.2.4] - 2026-07-13

新增

  • 交互终端中,anolisa update --check 现会在检查更新时显示进度。
  • 交互终端中,anolisa upgrade 现会在规划和执行升级时显示进度。

修复

  • Raw 组件安装和更新现可在同时存在二进制发布包时选中可安装归档包。

[0.2.3] - 2026-07-12

变更

  • 软件包安装和卸载进度现输出至标准错误,避免干扰重定向结果。

修复

  • 下游管道提前关闭标准输出时,ANOLISA 命令现可正常退出。
  • 标准输出写入失败时,ANOLISA 命令现会报错而非静默成功。

[0.2.2] - 2026-07-09

新增

  • anolisa update --check 现可只读报告 RPM 升级机会。
  • anolisa update --check --motd 现可输出简短登录升级提示。
  • anolisa upgrade 现可应用 RPM 工具链升级。
  • anolisa upgrade 现可安装目标配置缺失默认组件。
  • anolisa adapter scan 现将缺失来源的启用记录标为 orphaned。
  • anolisa adapter status 现将缺失适配器来源报告为降级。

变更

  • anolisa list 现显示可见用户和系统记录的 scope。
  • anolisa status 现显示 scope、可变性、遮蔽和状态路径。
  • anolisa doctor 现在用户模式诊断可读系统组件。
  • anolisa doctor 现为只读系统记录建议系统模式命令。
  • anolisa update --check 未指定 --target 时使用最新目标配置。
  • anolisa update --check --motd 现提示用 sudo anolisa upgrade

修复

  • anolisa uninstallforgetupdate 现拒绝只读系统目标。
  • anolisa upgrade 现将未解析默认组件报告为检查错误。
  • anolisa upgrade 刷新 RPM 详情失败时现会提示。

[0.2.1] - 2026-07-08

新增

  • anolisa adapter enable 现支持 cosh、Codex、Claude Code 的 Tokenless 适配器。
  • anolisa adapter enable 现支持 Qoder Tokenless 适配器。

变更

  • Claude Code 适配器现使用组件专属 marketplace。
  • anolisa adapter enable 现先拒绝无效适配器类型。

修复

  • Codex 适配器现可使用已打包数据目录资源。
  • Qoder 启用遇到损坏 settings.json 时不再覆盖。
  • Qoder 禁用现只移除 ANOLISA 添加的 hook。
  • Qoder 适配器现优先使用稳定版 qodercli。

[0.2.0] - 2026-07-07

新增

  • Raw 组件现可声明 conflicts 阻止不兼容安装。

修复

  • anolisa install 现会在变更主机前拒绝 Raw 组件冲突。
  • anolisa install --dry-run 现报告 Raw 组件冲突,不再显示无效计划。

[0.1.20] - 2026-07-03

新增

  • ANOLISA 现可通过 @anolisa/cli 发布 Linux x64 和 arm64 二进制。
  • repo.toml 现启用 npm 后端用于组件分发。

变更

  • anolisa list 现显示本地状态、归属和下一步操作。
  • anolisa list --json 现包含 RPM 包名、版本、架构和来源。

修复

  • RPM 安装和更新现可继续使用系统软件源解析依赖。
  • Adapter 命令现区分缺失清单和无效清单。

[0.1.19] - 2026-07-02

修复

  • anolisa adapter disable --dry-run 现只预览清理。
  • 只读命令保存 repo.toml 失败时仍可使用已下载配置。
  • 组件命令现可一致接受软件包别名。
  • 模糊软件包别名不再误选已安装组件。
  • 未知组件名不再先查询软件包。

[0.1.18] - 2026-07-01

新增

  • anolisa install 系统模式现自动安装缺失系统包。
  • anolisa install --dry-run 现标出依赖处理方式。
  • anolisa install 现显示自动安装的系统包。
  • anolisa status --verbose 现显示组件自动安装包。

变更

  • 需要仓库的命令现首次使用会下载 repo.toml
  • 仓库配置 dry-run 现只校验不写入。
  • RPM 安装和更新现只使用 repo.toml 源。
  • 用户模式 raw 安装现先提示缺失依赖。
  • raw 安装失败现提示已保留的自动安装包。
  • anolisa update self 不再预先获取仓库配置。

修复

  • anolisa list --installed 现包含已收编 RPM。
  • anolisa list 现显示 adopted、failed、disabled 状态。
  • Adapter 命令现优先使用契约所在数据目录资源。
  • 缺少 [backends.rpm] 时 RPM 安装不再调用 dnf
  • RPM 更新缺少 [backends.rpm] 时不再使用主机源。

[0.1.17] - 2026-06-30

新增

  • 仓库 components.toml 现可声明组件与包名映射。
  • anolisa list --installed 现过滤已安装组件。

变更

  • anolisa listinstall --all 现读取 components.toml
  • anolisa list 现显示 NAME、SUMMARY、BACKENDS、STATUS。
  • anolisa list --enabled 现作为隐藏别名保留。
  • ANOLISA_CATALOG_URL 不再控制列表来源。
  • installstatusadoptrepair 现解析 RPM 包别名。
  • anolisa status 现提示用 sudo anolisa adopt 收编 RPM。

修复

  • status <RPM 包> 现显示规范组件行。
  • repair <RPM 包> 现刷新规范组件行。
  • 非 root osbase 变更命令现可进入系统 helper。
  • root 用户模式现会在写入前被拒绝。
  • 缺少 sudo 的系统模式写入现提前失败。
  • 旧符号链接安装不再误报完整性失败。
  • status 现报告符号链接目标不匹配。

[0.1.16] - 2026-06-29

新增

  • anolisa osbase sandbox install runc 现安装 runc、containerd、Docker 和客户端。
  • anolisa osbase sandbox install 现启用场景声明的服务。
  • anolisa osbase sandbox install 现执行场景安装校验。
  • anolisa osbase sandbox install 现记录沙箱安装状态。
  • anolisa osbase sandbox install 现提示可选场景包。
  • rundfirecrackergvisor 场景现声明安装校验。
  • anolisa adapter enable 现支持 adapter_type = "skill_bundle"
  • RPM 包现安装默认 /etc/anolisa/repo.toml
  • ANOLISA 遥测现为 .jsonl 运维日志配置轮转。

变更

  • anolisa osbase sandbox install --dry-run 现显示五个安装阶段。
  • anolisa osbase sandbox install runc 现要求 Linux 4.18 及以上。
  • anolisa osbase sandbox install 校验失败现作为警告报告。
  • repo.toml 默认 RPM 源现指向 agentic-os 路径。
  • anolisa update self --json 现包含 RPM 包和版本信息。
  • anolisa adapter status 现不要求技能包注册插件。
  • anolisa adapter enable 现拒绝带配置的技能包。

修复

  • RPM 相关命令现默认用组件名作为包名。
  • anolisa update self 现通过 dnf 更新 RPM 安装。
  • 非 root 沙箱安装现显示完整阶段结果。
  • ilogtail 安装脚本需 bash 时现能正常运行。
  • anolisa adapter disable 清理技能包时不再报插件卸载错误。

[0.1.15] - 2026-06-25

新增

  • anolisa doctor 现输出组件健康、依赖和修复建议。
  • raw 组件现可声明运行依赖供安装和更新检查。
  • anolisa install --dry-run 现预览 raw 组件依赖状态。

变更

  • anolisa installupdate <component> 缺依赖时先停止。
  • anolisa restart <component> 现重启 RPM 组件服务。
  • anolisa restart <component> 遇到 RPM 模板服务时给出指引。

修复

  • anolisa adapter enable 现按包内元数据展开 {datadir}
  • anolisa uninstallforget 后 adapter 不再见旧元数据。

[0.1.14] - 2026-06-24

新增

  • raw 组件现可用 {unitdir} 放置系统单元。
  • raw 组件现可用 {userunitdir} 放置用户单元。
  • 用户模式 anolisa install 现会激活用户服务。

变更

  • 用户模式 anolisa install 现将 %u 展开为当前用户。
  • 系统模式 anolisa install 现保留 %u 用户模板。
  • anolisa uninstall 删除单元文件后现会重载 systemd。
  • anolisa restart <component> 现会重启用户服务。

修复

  • anolisa install 现无需手动重载即可启动新单元。
  • anolisa uninstall 现会停用用户模式安装的服务。
  • anolisa adapter enable 现从包目录查找 {datadir} 技能。

[0.1.13] - 2026-06-23

新增

  • anolisa adapter enable 现支持 Hermes 插件。
  • anolisa adapter enable 现安装声明的 OpenClaw 技能。
  • anolisa adapter enable 现写入声明的 OpenClaw 配置。
  • anolisa install 现启动 raw 组件声明的服务。
  • anolisa install 现设置 raw 组件声明的文件能力。
  • anolisa install 现执行 raw 组件声明的钩子。
  • anolisa update <component> 现重启 raw 组件声明的服务。
  • anolisa update <component> 现重设 raw 组件声明的文件能力。
  • anolisa uninstall 现执行 raw 组件卸载钩子。
  • anolisa uninstall 现停用已停止的声明服务。

变更

  • anolisa adapter scan 现按声明位置查找资源。
  • anolisa adapter enable 现读取包内适配器资源。
  • anolisa install --dry-run 现预览 raw 文件能力。
  • anolisa register status 现显示最新注册记录。
  • 取消 anolisa registerunregister 不再报错。

修复

  • anolisa adapter status 现能识别换行的 OpenClaw 表格。
  • anolisa adapter status 检查 Hermes 时忽略内置插件。
  • anolisa adapter 现能找到 RPM 组件附带的元数据。
  • anolisa register status 现显示 sysom 控制台注册。

[0.1.12] - 2026-06-22

新增

  • anolisa update <component> 可更新 raw 组件。
  • anolisa osbase sandbox list 可显示 sandbox.toml 场景。
  • anolisa osbase sandbox uninstall <scenario> 可移除场景软件包。
  • anolisa system setup 可为非 root osbase 命令安装助手服务。
  • anolisa system status 可显示助手健康状态。
  • anolisa system teardown 可移除助手服务和沙箱配置。
  • anolisa env --json 现包含发行版身份字段。

变更

  • anolisa osbase sandbox install <scenario> 现按 sandbox.toml 安装场景。
  • 未指定 --install-mode 时,root 用 system,普通用户用 user
  • anolisa update <component> --dry-run 现显示 raw 候选版本。

修复

  • yum 后端名现会作为 rpm 处理。
  • --package 安装的 raw 组件更新时复用包名。
  • anolisa update <component> 不再允许 raw 降级。
  • anolisa update <component> 无法比较版本时不再替换文件。

[0.1.11] - 2026-06-18

新增

  • anolisa adopt <component> 可接管预装 RPM。
  • anolisa repair <component> 可刷新漂移的 RPM 状态。
  • anolisa forget <component> 可停止跟踪组件。

变更

  • anolisa status <component> 现报告 RPM 状态漂移。
  • anolisa uninstall 默认保留观察到的系统 RPM。
  • anolisa install 接管 RPM 时保留适配器资源。

[0.1.10] - 2026-06-17

新增

  • anolisa install --backend rpm 可通过 dnf 安装缺失 RPM 组件。
  • anolisa install 可接管匹配的预装系统 RPM。
  • anolisa update <component> 可通过 dnf 更新 RPM 组件。
  • anolisa status 现显示 RPM 组件的软件包来源。
  • anolisa status <component> 现显示匹配的未跟踪系统 RPM。

变更

  • anolisa update runtime <component> 改为 anolisa update <component>
  • repo.toml 现使用 [backends.rpm] 替代 [backends.yum]
  • anolisa install --all 现在批量摘要列出接管的 RPM。

修复

  • anolisa install --all 现在普通输出显示各组件失败原因。
  • anolisa install 在缺少 rpmdnf 时提示 --backend raw
  • anolisa install 不再覆盖先完成的 raw 安装。

[0.1.9] - 2026-06-16

新增

  • anolisa install --all 可安装目录中的所有可用组件。
  • anolisa install --all --fail-fast 可在首个失败组件后停止。
  • anolisa install --all --json 现返回按组件汇总的批量结果。
  • anolisa status 现显示已安装组件的适配器摘要。

变更

  • installed.toml 现区分 ANOLISA 管理包和只观察的系统 RPM。

[0.1.8] - 2026-06-15

新增

  • anolisa adapter enable 现可将已安装适配器注册到 OpenClaw。
  • anolisa adapter disable 现可移除 OpenClaw 适配器注册。
  • anolisa adapter status 现可报告 OpenClaw 适配器健康状态。
  • anolisa adapter scan 现可显示已安装适配器资源。

变更

  • anolisa install 现会放置后续启用所需的适配器资源。
  • anolisa uninstall 现会阻止移除仍有启用适配器的组件。

[0.1.7] - 2026-06-13

变更

  • 用户态库路径调整为 ~/.local/lib/anolisa;其余目录继续遵循 XDG_* 环境变量覆盖。

修复

  • anolisa install 不再要求本地已有组件目录条目即可从远程仓库下载安装。
  • anolisa install --dry-run 无需下载完整安装包即可预览文件和服务列表。

[0.1.6] - 2026-06-12

新增

  • anolisa osbase sandbox install gvisor 支持 standalone、containerd 和 substrate 三种部署形态。(#851)
  • anolisa list 可从 repo.toml 配置自动发现组件目录。(#854)

变更

  • 废弃旧版"能力"模型,统一为组件生命周期;旧状态在下次写入时自动迁移。(#876)

修复

  • anolisa list --enabled 现在正确显示已安装组件,而非空列表。(#872)
  • anolisa list 在已配置 repo.toml 时不再要求额外的本地目录文件。(#854)

[0.1.5] - 2026-06-11

新增

  • anolisa list 从远程或本地组件目录读取并返回结构化 JSON。(#850)
  • anolisa install <组件> 从远程仓库下载、校验并安装组件。(#852)
  • anolisa uninstall 支持新组件模型,同时保留旧版回退。(#852)

变更

  • 简化 CLI 帮助输出,围绕 listinstalluninstallstatusdoctorlogsrestartupdate 重新分组。(#850)

修复

  • 未配置组件目录时,anolisa list 返回空列表并提示配置方法。(#850)
  • 安装中途失败时自动回滚已写入的文件。(#852)

[0.1.4] - 2026-06-10

新增

  • anolisa adapter scan 探测已安装的 Agent 框架集成。(#808)
  • anolisa adapter install 下载校验后的安装包并注册到目标框架。
  • anolisa adapter remove 安全移除 ANOLISA 管理的文件,支持预览和 dry-run。
  • anolisa adapter install tokenless openclaw 通过 OpenClaw CLI 注册 tokenless 适配器。
  • anolisa enable 从远程仓库获取组件元数据,离线时降级到本地缓存。
  • anolisa status 输出中新增组件健康检查结果。

变更

  • 订阅管理命令提升为顶层 anolisa register / unregister

修复

  • adapter 安装或移除失败时自动回滚或保留状态以便重试。

[0.1.3] - 2026-06-09

新增

  • anolisa --help 按类别分组展示命令(日常操作 vs. 管理命令)。
  • list 命令在帮助中展示 ls 别名。
  • anolisa update self 成功后输出 changelog 链接。

变更

  • 修正包 license 元数据为 Apache-2.0。

[0.1.2] - 2026-06-08

新增

  • anolisa bug 生成本地诊断报告,包含环境信息和近期错误日志。
  • anolisa self update 作为 anolisa update self 的别名。

修复

  • 恢复 bug report issue 模板。

[0.1.1] - 2026-06-07

新增

  • anolisa osbase sandbox install 一键部署沙箱环境(支持 firecracker 和 e2b 后端)。
  • anolisa register / unregister 管理数据上传授权,支持 30 天延后。
  • anolisa enable 可配置日志上传(ilogtail),自动探测地域。
  • anolisa update self 下载并应用 CLI 更新,含完整性校验和失败回滚。
  • 真实的 dnf/apt 包管理器后端,替换占位实现。
  • anolisa 工作区 GitHub Actions CI。

修复

  • 安装脚本改用 bash 参数展开替代 sed,提升可移植性。

[0.1.0] - 2026-06-04

ANOLISA CLI 首个 alpha 版本。

新增

  • CLI 命令:envliststatuslogsenabledisableuninstallrestartupdateinfodoctor
  • 环境探测:OS、架构、内核、发行版、容器运行时、用户身份(探测失败时优雅降级)。
  • 组件生命周期引擎:先预览再执行,含完整性校验和操作日志。
  • 配置驱动的上线门控,新能力无需改代码即可发布。
  • 声明式 TOML 组件清单,支持多架构。
  • install-anolisa.sh 安装器:三种模式(本地、checkout、URL),支持校验和 --dry-run
  • agent-observability 和 token-optimization 端到端冒烟测试。

已交付能力

能力状态
agent-observabilityenable 完整链路(dry-run + 真实执行)
其余 9 个仅清单;enable 返回 NOT_IMPLEMENTED

已知限制

  • 真实执行路径仅限 Linux(darwin 宿主只能 --dry-run)。
  • 尚无签名校验和 rpm/deb 后端。
  • update 命令返回 NOT_IMPLEMENTED。

变更日志

本文件记录 ANOLISA Blaze 的所有重要变更。

格式基于 Keep a Changelog, 版本号遵循 语义化版本

[未发布]

[0.3.0] - 2026-07-22

新增

  • 通用 StorageProvider trait,支持可插拔存储后端架构。
  • FileStorageProvider:默认文件存储后端,适用于开发和标准部署。
  • [storage] 配置段:providerpool_sizepreforkflush_interval 字段,均有向后兼容的默认值。
  • GET /v1/health 现返回 storage_pool 状态(ready/capacity/pending)。
  • BackendSpawner trait 扩展 restorepauseresumecreate_snapshot 方法(默认返回不支持,为后续快照工作流预留接口)。

[0.2.1] - 2026-07-21

变更

  • 品牌重塑:组件从 Anvil 更名为 Blaze。二进制:blazed,配置路径:/etc/anolisa/blaze/,状态目录:/var/lib/blaze/
  • Firecracker vCPU 配置现已校验上限(1–32)。

新增

  • 组件已注册到项目清单(根 README、AGENTS.md、PR 模板)。
  • VM 资源配置回退链已在 README 中说明。

[0.2.0] - 2026-06-30

新增

  • FirecrackerSpawner:支持 Firecracker microVM 后端,daemon 启动时自动探测并选择最强隔离。
  • TCP 远程 API:可配置 [listen].http_addr 开启 TCP 监听(端口 14159),供平台远程调用。
  • 优先级后端选择:build_spawner() 按 firecracker → linux-sandbox → mock 优先级自动选型。
  • Storage section:[storage].images_dir 统一管理 vmlinux/rootfs 查找路径。
  • 打包骨架:dist/anvil.service(systemd unit)+ anvil.spec(RPM)+ tmpfiles-anvil.conf
  • [backends] 配置段,直接映射后端二进制路径。

[0.1.3] - 2026-06-24

变更

  • sandbox 进程现在运行在完整 namespace 隔离中(PID、网络、文件系统)。

[0.1.2] - 2026-06-22

新增

  • daemon 现在管理 sandbox 进程生命周期:创建时自动启动,销毁时自动终止。
  • backend 二进制不可用时优雅降级(便于开发环境使用)。

[0.1.1] - 2026-06-20

新增

  • Policy 校验在 sandbox 启动前拒绝不安全的配置。
  • osbase sandbox uninstall 安全协调(防止移除正在使用的 backend)。

[0.1.0] - 2026-06-18

ANOLISA Anvil 首个骨架版本。

新增

  • 通过 HTTP API 创建、列出、查看、checkpoint(仅状态转换)、reset、销毁 sandbox。
  • 策略驱动的 backend 选型:指定 workload class 即可自动匹配合适的 sandbox 类型。
  • Warm pool:预创建 sandbox 随时分配,可配置 min/target/max 容量。
  • 模板共享:多个 sandbox 共用一份 base 内存镜像,降低单实例内存开销。
  • Prometheus metrics 端点,供监控系统采集。

Changelog

2.8.0

  • Added COSH_SESSION_ID export for subprocess and MCP correlation. (#1491)
  • Fixed hook process tree termination on timeout and cancellation. (#1585)
  • Updated docs to centralize user guides and add docs lint CI. (#1586)
  • Fixed cosh-switch to reuse compatible cosh-ng authentication. (#1951)

2.7.0

  • Added /ktuner command with consent-gated, opt-in first-run check and trusted-path resolver. (#1279)
  • Added loading indicator when selecting an auth provider. (#1389)
  • Added COSH_SESSION_ID export for agentsight per-run correlation. (#1383)
  • Fixed security intents to map to hook commands. (#1438)
  • Fixed cosh-switch post-switch guidance for clarity. (#1424)
  • Fixed shell mode to add actionable error guidance for exit code 127. (#1319)
  • Updated docs to rename __CN.md to __zh.md, fix cross-refs, and add missing READMEs. (#1335)

2.6.1

  • Added npm packaging support for CLI and cosh. (#1307)
  • Added multi-hook toggles support. (#1206)
  • Fixed tips banner to stay visible after initial login. (#1308)
  • Fixed Ctrl+O to prioritize error details over compact mode. (#1202)
  • Fixed system-profile BINDIR to follow PREFIX. (#1193)
  • Fixed AfterModel hook non-blocking notifications not surfacing. (#1182)
  • Updated component docs to migrate into user-guide and developer-guide. (#1295)
  • Added copilot-shell zh/en user and developer docs. (#1236)
  • Fixed CONTRIBUTING.md file mode from symlink to regular file. (65601f06)

2.6.0

  • Added multi-hook enable and disable support to /hooks. (#1200)
  • Added cosh-ng compatibility with cosh-switch. (#1169)
  • Added instance_id to SysOM API request params. (#1160)
  • Added anolisa component contract. (#1128)
  • Added SLS JSONL session telemetry with expanded metrics. (#1057)
  • Added authenticated models display in /model dialog. (#1030)
  • Added kitty csi-u keys support with sequence timeout management. (#552)
  • Added large paste placeholder and fixed placeholder id reset on esc cancel. (#312)
  • Fixed SLS log write to skip when file does not exist or is not writable. (#1101)
  • Fixed useless sandbox guard and failure handler hooks by removing them. (#979)
  • Fixed missing keyboard shortcut hints in footer status bar. (#921)
  • Fixed response language and model identity rules. (#920)
  • Fixed sub-model refusal detection and byteLength display. (#895)
  • Fixed webfetch sub-model output validation to avoid silent refusals. (#895)
  • Fixed thinking output to be distinguished from user input with prefix and color. (#894)
  • Fixed custom model configuration to be preserved. (#887)
  • Fixed partial message finalization on API error. (#801)
  • Fixed API error reporting in all output formats, not only text. (#801)
  • Improved escape key handling by unifying it in appcontainer. (#437)

2.5.0

  • Fixed missing esc hint in tool confirmation footer status bar (#732)
  • Fixed invisible cursor in provider/auth config inputs (#683)

2.4.1

  • Fixed HookSystemMessage rendering as info and resolved Content/Thought duplication (#636)
  • Fixed prompt ids to remain monotonic after shell remount (#628)

2.4.0

  • Added DashScope Token Plan provider entry to the OpenAI-compatible auth dialog. (#598)
  • Added UserPromptSubmit and PostToolUse hook reason surfacing in the UI. (#545)
  • Added run_id field to HookInput for per-run event correlation. (#482)
  • Fixed UserPromptSubmit hook decision merging to enforce safety priority over allow. (#597)
  • Fixed missing tool_use_id in PreToolUse hook input. (#559)
  • Fixed memory hooks lock takeover with atomic rename and async IO. (#550)
  • Fixed auto-memory workspace cleanup wiping user-added directories. (#548)
  • Fixed auto-memory session hook missing read_file events due to wrong arg key. (#547)
  • Fixed run_id ordering by setting it before UserPromptSubmit hook fires. (#537)
  • Fixed UserPromptSubmit hook firing on tool-result and Stop continuations. (#534)
  • Updated installer to support multiple install profiles. (#541)

2.3.0

  • BREAKING Removed qwen-oauth authentication support. (#455)
  • Added auto memory background extraction system. (#465)
  • Added full shell command display in hook-ask and exec confirm dialogs. (#452)
  • Added esc key to cancel running slash commands. (#290)
  • Fixed JavaScript heap out of memory during long sessions. (#462)
  • Fixed missing allow decision reason in UI when systemMessage is absent. (#435)
  • Improved test coverage with standalone tests for ExecCommandPreview. (#460)
  • Updated hook docs to clarify difference between systemMessage and reason. (#436)

2.2.1

  • Fixed initial chat being blocked during skill/subagent first-load discovery. (#418)
  • Fixed missing tool_use_id in PostToolUse hook event payload. (#414)
  • Fixed missing skill_context in PreToolUse hook input for resolved skill path. (#409)
  • Fixed missing auto-completion for /statusline subcommands. (#408)
  • Fixed unavailable agents appearing in the key sharing prompt. (#394)
  • Fixed bash option not being restored after canceling from the provider screen. (#393)
  • Fixed hook systemMessages to be concatenated with a [name] prefix for clarity. (#387)

2.2.0

  • Added ask decision support for UserPromptSubmit hook. (#328)
  • Added new command for Clawhub CLI. (#313)
  • Added interactive Skills TUI Panel with enable/disable support. (#311)
  • Added variable substitution and display control for extension TOML commands. (#291)
  • Added immediate hook activation on extension install/uninstall. (#283)
  • Added ask decision support for PreToolUse hooks. (#276)
  • Added configurable status bar. (#251)
  • Added /export command for session history. (#245)
  • Fixed API key validation to skip non-Dashscope providers. (#337)
  • Fixed PreToolUse ask dialog by unifying it to info type with diff preview. (#345)
  • Fixed memory leak in memory management. (#309)
  • Fixed extension lifecycle reliability. (#298)
  • Fixed hook registry sync on extension enable/disable. (#298)
  • Fixed interface crash caused by leftBottomContent of Box nested in Text in Footer. (#293)
  • Fixed /hooks install command by removing it and adding default help. (#287)
  • Fixed extension examples installation and package configuration. (#271)

2.1.0

  • Added startup bash entry and simplified manual auth dialog. (#217)
  • Added async fzf-based tab completion optimization. (#214)
  • Fixed OpenAI API key and model validation via /models endpoint on auth. (#243)
  • Fixed API key retention when navigating to apiKey field in auth dialog. (#241)
  • Fixed node-pty native binary bundling for both linux architectures. (#232)
  • Fixed stream redaction by replacing integer offset with committed text reference. (#210)
  • Fixed missing fields in hook system. (#188)

2.0.4

  • Added STS authentication support via ECS RAM role. (#161)
  • Added BeforeModel, AfterModel, and BeforeToolSelection hooks. (#154)
  • Added sandbox usage summary on session exit. (#137)
  • Added Tab-completion for ! shell mode. (#131)
  • Fixed config-dir source unification and prevented ~/.copilot creation on startup. (#171)
  • Fixed /bug command crash in headless environment. (#175)
  • Fixed undefined metrics.sandbox in StatsDisplay. (#171)
  • Supplement /hooks install step to post-installation guide. (#142)
  • Supplement hooks documentation (index, reference, writing-hooks). (#142)

2.0.3

  • Migrated config directory from ~/.copilot to ~/.copilot-shell. (#78)
  • Added API key detection from configured agents with user approval on bootstrap. (#127)
  • Added support for configuring multiple custom model providers. (task#80737766)
  • Added global API endpoint support for Dashscope. (#133)
  • Added custom skill paths support via settings.json. (#128)
  • Added support for loading skills from extension directories with cosh-extension.json compatibility. (#54)
  • Added /bug command for submitting bug reports. (#122)
  • Added sandbox-guard install command with bypass approval flow. (#125)
  • Added secret redaction for model output and tool results. (#100)
  • Added extensible feature tip banner for first-launch guidance. (#113)
  • Added built-in /dir cd command for in-session directory navigation. (#19)
  • Added session renaming command. (task#80737766)
  • Added nvm-aware Node.js detection in cosh wrapper script. (#72)
  • Added system-level install via Makefile with FHS-compliant directory layout. (#72)
  • Fixed 24-item limit on @ file completion menu. (#92)
  • Fixed TUI flicker on Qwen OAuth page in limited-height terminals. (#76)
  • Fixed left-arrow key not wrapping from line start to previous line end. (#53)
  • Fixed irrelevant info display in /model command. (#85)
  • Fixed credentials encryption support in settings.json. (#90)
  • Fixed test failure when running as root user. (#29)
  • Fixed pre-commit hook working directory for lint-staged. (#90)
  • Configured Husky hooks and documented pre-commit setup. (#65)

2.0.1

  • Renamed OpenAI authentication label to "BaiLian (OpenAI Compatible)" for clarity.
  • Fixed login shell stdin drain to prevent unwanted input echo.
  • Removed ripgrep unavailable warning message.

2.0.0

  • Synced upstream qwen-code to v0.9.0 and rebranded to Copilot Shell.
  • Bumped version directly to 2.0.0 (skipping 1.x, which was used by a previous OS Copilot release).
  • Integrated Skill-OS online remote skill discovery with priority-based fallback (Project > User > Extension > Remote).
  • Added /skills remote and /skills cache clear commands for remote skill management.
  • Added /bash interactive shell mode
  • Added -c argument support for inline bash commands.
  • Added PTY mode for sudo command support.
  • Added hooks system with PreToolUse event for intercepting tool calls before execution.
  • Added new model provider named Aliyun
  • Added nested startup detection warning banner.
  • Added system-wide skill path (/usr/share) support.
  • Removed original Gemini sandbox.
  • Fixed skill frontmatter parsing for YAML special characters (|, &, >).
  • Fixed login escaped character echo issue in ECS workbench.
  • Fixed Linux headless environment browser open failure when auth with Qwen OAuth.
  • Fixed Qwen OAuth authentication, replay, and UI rendering issues.
  • Fixed exception handling when adding workspace directories.
  • Fixed user query start with unix path being misidentified as command.
  • Fixed API key display explicitly.
  • Fixed Chinese i18n for /resume command.
  • Improved ? hint visibility — hidden while user is typing.
  • Miscellaneous UI, branding, CI, and build improvements.

Changelog

All notable changes to the cosh-ng project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[0.16.0] — Unreleased

[0.15.0] — 2026-08-09

Fixed

  • Restore hint cursor after inline hints in shell (#2172)
  • Support ID_LIKE fallback for OS distribution detection (#2200)
  • List hook commands in /help output (#2208)
  • Skip audit logs for service lifecycle actions (#2213)
  • Support macOS-specific file reads in core (#2220)
  • Serialize handoff state to prevent race conditions (#2226)
  • Normalize apt search glob patterns (#2227)
  • Recover context budget after compaction in core (#2244)
  • Deduplicate hook notices in shell (#2259)

[0.14.0] — 2026-08-04

Added

  • /status, /about, and /stats slash commands for runtime introspection (#1778)
  • /mcp slash command for MCP server management (#1949)
  • /session list --all to enumerate sessions across workspaces (#2139)
  • DashScope prompt cache support to reduce token cost (#2046)
  • cached_tokens observability for cache-hit diagnostics (#2075)
  • Dynamic max_tokens by model in the OpenAI provider (#2165)
  • Advertise roots capability in MCP client initialization (#2007)
  • Hook tools and environment support in core (#1894)
  • Surface tool-argument status and cap retries across core and shell (#1925)
  • Auto-execute fully readonly compound commands in shell (#1959)
  • Extend capped runs across core and shell (#2035)
  • Improved auth menu across core and shell (#2062)
  • Bound agent handoff input-waits in shell (#2168)

Changed

  • Terminal-agnostic multi-line prompt entry in shell (#1947)

Fixed

  • Shell handoff and hooks: preserve LLM input, drop stale handoff text, resume handoff fallback within a provider session, redact handoff evidence, close secret-redacted handoffs via one-time claim token, converge Han NL input ownership, route sensitive NL to agent, and run project hooks for send-to-shell (#1955, #2010, #2055, #2074, #2130, #2137, #2151, #2154)
  • Approval lifecycle: guarantee terminal state with lifecycle ledger and last-resort timeout, rearm auth input, surface sandbox-bypass approval in trust mode, and reject zero idle timeout (#1934, #1939, #1968, #2116)
  • Auth flows: step /auth back on ESC, list /auth in /help, and hint /auth on noauth startup (#1891, #1906, #2166)
  • Slash command and prompt input: prevent slash echo duplication on intercept, let Up recall slash commands, intercept slash-bearing NL prompts, support soft newline in NL prompts, keep card submit type-ahead, normalize CSI-u backspace, and key ghost ownership by route (#1868, #1899, #1911, #1922, #1942, #1993, #2167)
  • Shell rendering: stop extdebug leak into prompt hooks, highlight code-block syntax, reply in user language, compact skills list, and disable implicit pagers (#1849, #1904, #1910, #1921, #1998)
  • Command risk and safety: assess all compound-command segments for risk, gate irrecoverable system-control commands, and classify interpreter risk (#1905, #2081, #2119)
  • File IO hardening: reject placeholder writes, make file writes atomic, bound and confine read tools, restore blocking before drop-write, and treat fd-dup redirect as non-write (#1918, #2069, #2120, #2121, #2124, #2127)
  • Shell recovery and drift: prevent recovery storms and use zsh preexec $3 for drift (#2072, #2073)
  • Audit logging: show hook context (#2082)
  • Core runtime: preserve tool arguments, align compaction, show real session prompt, fail closed on emit error, and make truncation UTF-8-safe (#1844, #1847, #2003, #2005, #2118)
  • Types, wire, and packaging: fix wire errors, drop cross-workspace dev-dep, align RPM identity, align bundle health checks, and add base-dir hint in skill tool (#1514, #1933, #1937, #1984, #2140)

[0.13.0] — 2026-07-26

Added

  • Interactive session recovery via /session, /resume, and the --resume launch option (#1546, #1592)
  • Workspace-scoped session persistence with schema versioning and legacy-session migration (#1546, #1592)
  • MCP tool support for extensible agent capabilities (#1530)
  • Contextual shell insight interactions (#1537)
  • Secret redaction across core and shell layers (#1555)
  • Diagnostic bundle export via cosh doctor (#1576, #1597)
  • Extension platform in core and shell (#1583)
  • Personalized prompt recommendations (#1606)
  • Session compaction to manage persistence growth (#1668)
  • PostToolUse response replacement and hook adaptation (#1669)
  • Gated startup suggestions (#1671)
  • Audit logging across core and shell (#1679)
  • Improved session UX with slash command refinements and sysom /auth shortcut (#1726, #1813)
  • Route unresolved natural-language input to Agent (#1742)
  • Cancel active agent runs with ESC (#1761)
  • Turn-scope batch approval consent (#1825)

Changed

  • Revert persisted credential encryption (#1748)
  • Align task scope documentation (#1445)
  • Stabilize core and shell test gates (#1699)
  • Speed up raw CLI tests and fake stream pacing (#1797)
  • Track cosh-shell test inventory at 2469 (#1827)

Fixed

  • Session command parsing, signal exits, slash argument handling, and prompt ghost ESC (#1632, #1634, #1636, #1663, #1724, #1843)
  • Agent question interaction, suggestion controls, recommendation scopes, and tab redraw (#1725, #1741, #1749, #1758, #1821)
  • Approval card layout, blocked-title alignment, and empty enter handling (#1786, #1788, #1838)
  • Auth and trust hardening: validate providers, harden auth, preserve trust blocks, encrypt credentials, and expand paths (#1627, #1673, #1701, #1722, #1777, #1784, #1791, #1809, #1816, #1841)
  • Audit logging fixes: kill trees, split compound commands, redact secrets, scope claims, and preserve export path (#1611, #1613, #1635, #1765, #1772, #1840, #1842)
  • Core runtime stability: JSONL validation, tool selection errors, streamed state, ai-like tables, revision clock, free-text clearing, layout gates, and SysOM terminator (#1599, #1661, #1689, #1730, #1731, #1799, #1800, #1803, #1839)
  • Platform and CLI correctness: honor dry-run, handle skipped checkpoints, allow search patterns, fix package dry-run/search results, respect cargo config, sync Bash HISTFILE, validate workspace paths, route --help to stdout, add skill arg checks, warn on redacted writes, skip DEBUG trap, restore utility tools, stop BASHOPTS extdebug leak, handle null redirection, keep provider handoffs alive, update DashScope URL, raw action relay watchdog, restore startup health row, hide receipt audit ref, and update test inventory baseline (#1426, #1440, #1633, #1637, #1642, #1646, #1672, #1675, #1676, #1710, #1719, #1733, #1783, #1787, #1790, #1795, #1808, #1812, #1818, #1820, #1845)

[0.12.0] — 2026-07-12

Added

  • Move authentication ownership into cosh-core with isolated config layers (f028ad90)

Changed

  • Consolidate logging under a unified runtime module (db86b3dd)
  • Migrate component docs into user-guide/developer-guide and add cosh-ng docs (317d3f26, adf63ac2)
  • Rename *_CN.md docs to *_zh.md and fix cross-references (82f8dab4)

Fixed

  • Honor svc dry-run across platform and cli (4c593050)
  • Preserve manual aliyun fallback and legacy STS auth (924dd76b, ee1dd179)
  • Protect auth provider edits; prioritize aliyun auth option (f0c97efa, 904655fb)
  • Bound host-executed shell preview (a6da7301)
  • Route noninteractive cosh launcher calls; support raw command passthrough (ecb56739, 1490eb3c)
  • Bind startup prompt and agent request context (14d6336f, 25d9d28f)
  • Own prompt boundary in shell (#1310)
  • Avoid UTF-8 split in loop detection (ef7f5147)
  • Remove provider-visible skill hints; guide diagnostic skill use (a6024873, 7f695178)
  • Drop redundant format borrow; satisfy clippy diagnostics (5e14a686, 063217f1)
  • Stabilize CI, raw-cli, PTY, and service tests (d573796d, 3563a5ab, 0fb34ea6, fc28da5f, ad138d45, 65421d25, 5b17b892, 3e43ba6e, 707bc3c0)

[0.11.0] — 2026-06-28

Added

  • Aliyun authentication provider with ECS auto-detection, STS credentials, and QR code flow
  • SysOM Aliyun provider with ACS3 signing for LLM API access
  • Per-turn SLS JSONL logging for observability
  • SysOM request source identification headers
  • Structured tracing logging system across all crates
  • Sandbox bypass approval flow on PostToolUseFailure hook events
  • Startup health scan for environment diagnostics
  • Extension/hook/skill enable/disable commands (/extensions, /hooks, /skills)
  • Unified component state management module
  • Dedicated HOOK approval panel with simplified UI
  • UserPromptSubmit hook with Ask approval enforcement
  • Shell evidence read admission control in cosh-core
  • Tool activity rendering in cosh-shell
  • cosh-switch hint in startup banner for toggling between cosh-ng and copilot-shell

Changed

  • BREAKING: Rename CLI binary from cosh to cosh-cli; remove dispatch_core
  • RPM spec: install cosh-cli binary, /usr/bin/cosh launcher, cosh-switch script, Conflicts: copilot-shell
  • Replace eprintln with structured tracing macros
  • Unify hook decision aggregation with fold_decision
  • Update workspace repository URL to github.com/alibaba/anolisa

Fixed

  • Auth ECS flow and panel overlap on phase transitions
  • Auth QR code rendered without ANSI escape codes
  • Use SysomProvider for aliyun after auth success
  • Align hook input fields and AfterModel/wrap_tool_response with copilot-shell protocol
  • tool_result dedup guard and visibility
  • Restore prompt before shell handoff
  • Suppress duplicate evidence reads
  • Reduce failed-command auto analysis noise
  • Skill existence check and harden approval matching
  • Resolve clippy warnings across cosh-core and cosh-shell

[0.10.0] — 2026-06-23

Added

  • Shell evidence protocol for capturing and replaying command execution context
  • Shell evidence control tool in cosh-core for evidence lifecycle management
  • Hook protocol aligned with copilot-shell for zero-change extension support
  • Per-hook decision propagation through notification protocol
  • Hook warnings rendered with per-hook decision color-coding in cosh-shell

Changed

  • Share agent error display text across cosh-shell modules

Tests

  • Cover shell evidence raw CLI flows

[0.9.0] — 2026-06-22

Added

  • Hook notifications integrated into approval panel with ⚠ warning display
  • Hook ask decisions enforce user approval even in Trust/Auto modes
  • Extended hook system with tool_use_id association and new event types
  • Registry protocol for /extensions /skills /hooks slash commands

Fixed

  • Show Registry group in /help output

Changed

  • Remove dead skill management code

[0.8.0] — 2026-06-18

Changed

  • Rename cosh-tui crate and binary to cosh-core across the entire workspace
  • Update adapter system: CoshTuiAdapterCoshCoreAdapter, AdapterKind::CoshTuiCoshCore
  • Update environment variable COSH_TUI_PATHCOSH_CORE_PATH
  • Update RPM spec, documentation, and all test fixtures

Fixed

  • Neutralize agent status text in streaming cards
  • Align streaming card widths in cosh-shell

[0.7.0] — 2026-06-17

Added

  • Extension discovery and loading module with cosh-extension.json manifest support
  • Extension hooks integrated into startup lifecycle
  • Skill module with multi-level loading (built-in, user, project) and hot-reload
  • SkillManager integrated into tool registry and startup
  • Available skills injected into system prompt for LLM discovery

Fixed

  • Infinite loop in expand_env_vars when environment variable is undefined
  • Warn on unsupported extension hook events (PostToolUseFailure, BeforeModel, AfterModel) instead of silently discarding
  • Align extension hooks format with copilot-shell nested group structure
  • Remove unused args parameter from skill tool schema to avoid misleading LLM
  • Show question free text answers in cosh-shell
  • Harden foreground shell handoffs
  • Share copilot shell config path and keep legacy config fallback

Changed

  • Normalize cosh-shell config keys
  • Standardize cosh-shell code and test organization
  • Move user state under copilot shell scope

[0.6.0] — 2026-06-16

Added

  • P0 hook system with 5 lifecycle events (on_session_start, on_turn_start, on_turn_end, on_tool_call, on_session_end) in cosh-tui
  • Shell approval classification and hook origin tracking in cosh-shell
  • Migrate current cosh shell into monorepo workspace

Fixed

  • Address approval review findings in cosh-shell
  • Harden shell evidence continuation to prevent dropped context
  • Normalize tool call streaming protocol in cosh-tui
  • Fix passthrough for subcommands in cosh-shell

[0.5.0] — 2026-06-15

Added

  • CoshTuiAdapter persistent process mode (spawn once, reuse across agent runs, auto-restart on death)
  • ask_user round-trip through control protocol (agent can ask inline questions routed to TUI)

Changed

  • Split cosh-tui main into cli/headless/interactive modules
  • Rename binary from cosh-tui-core back to cosh-tui

[0.4.1] — 2026-06-15

Added

  • settings.json → config.toml auto-migration with AES-256-GCM encrypted API key decryption
  • JSONL protocol and tool approval integration tests

Fixed

  • Prepend precmd in PROMPT_COMMAND to capture real exit code (Alibaba Cloud Linux /etc/bashrc issue)

[0.4.0] — 2026-06-15

Added

  • JSONL wire protocol (InputMessage / OutputMessage) for cosh-shell ↔ cosh-tui communication
  • Provider abstraction with OpenAI-compatible streaming (DashScope, OpenAI, DeepSeek, Generic profiles)
  • Tool execution framework with 7 built-in tools (shell, read_file, write_file, edit, grep, todo, skill) and approval control
  • Context window management, message truncation, loop detection, conversation compression
  • Lifecycle hooks framework
  • CoshCore agent loop engine
  • TOML-based multi-provider config with environment variable expansion

Changed

  • BREAKING: Binary interface from ratatui interactive TUI to JSONL stdin/stdout backend
  • BREAKING: Config format from settings.json to config.toml
  • Rewrite session store with single-file JSON persistence

Removed

  • Legacy ratatui-based TUI code (app, commands, llm, logger, theme, tools, ui modules)

[0.3.0] — 2026-06-15

Added

  • cosh-shell crate — PTY-based AI-augmented shell host with OSC marker protocol
  • Claude, Qwen, Fake AI adapters with streaming support
  • Inline rendering engine (approval, question, recommendation, activity panels)
  • Governance layer with approval modes
  • Terminal recovery via signal handlers (SIGTERM/SIGHUP/SIGQUIT) and panic hook
  • Exit code classification with 8 categories (Smart/Auto/Manual analysis modes)
  • Tool display engine with per-tool-type parsing and ANSI color categories
  • Hook engine with built-in hooks (FailedCommandHook, TestFailureHook) and skill routing
  • External hook loading from ~/.config/cosh/hooks/ with subprocess execution
  • Native shell compatibility (rcfile loading, PS1, history, login shell detection)
  • Context window with sliding window (max commands, max age, token budget)
  • Prompt intent optimization (do → Bash tool, know → prose)
  • Natural language intercept with visual feedback
  • InputClassifier conservative mode for native mode
  • Analysis throttle (30s cooldown, max 3 consecutive)
  • Consultation card rendering with keyboard capture
  • Control protocol for tool approval round-trips
  • Startup banner with gradient ASCII art logo
  • /mode and /hooks slash commands
  • Architecture documentation

Fixed

  • Native mode input rendering with powerlevel10k dual-line prompts
  • Slash/NL intercept via buffered-then-judge strategy in native mode
  • Zsh preexec intercept for command_not_found
  • CandidateRedraw line clearing for CJK input and backspace
  • Suppress cosh-osc$ prompt leak in native mode
  • Tool display label matching in bash tool executor
  • Wide character placeholder cell handling in buffer extraction

Changed

  • Unified workspace version (0.3.0) for all crates (cosh-types, cosh-platform, cosh-cli, cosh-shell, cosh-tui)

[0.2.0] - 2026-05-16

Hardening + audit-subsystem release. Workspace versions bumped to 0.2.0 together with the release profile and lockfile commit.

Added

  • audit subsystem with PEP/PDP/log split: cosh audit check / cosh audit log for command-safety gating and per-session retrieval.
  • Workspace release profile (opt-level = 3, lto = true, strip = true, codegen-units = 1), committed Cargo.lock, workspace-level dependency pinning, and native CA cert support.
  • Command timeouts, input validation, and panic-safe JSON output across cosh-cli and cosh-platform so a panic still emits a CoshResponse envelope on stderr instead of an empty exit.
  • forbid(unsafe_code) on cosh-cli / cosh-platform, plus svc list --state filter validation against an allow-list.
  • pkg search cross-references installed status so results show which matches are already installed.
  • ResponseMeta.warning field for non-fatal warnings; audit responses are explicitly marked as stub via this field.
  • LLM tool surface expansion in cosh-tui: pkg / svc / checkpoint wrapper tools, plus svc enable / svc disable --dry-run.
  • Timeouts + exponential-backoff retries on LLM and external command tools in cosh-tui; 60 s shell-tool timeout.

Changed

  • TUI /help aligned with the full command set; title bar version and markdown prefix stripping corrected.
  • Clippy warnings resolved across the workspace; dead-code allowances dropped; test code aligned with production lint level.
  • Build warnings eliminated and version detection improved across cosh-tui / cosh-platform.

Fixed

  • Shell safety check tokenized to close tab / newline / redirect / chain bypasses; substring matching on raw command strings replaced with whitespace (incl. \t / \n / \r) tokenization and metacharacter rejection (; | & > < $ ` ( ) { }) — is_safe_command in crates/cosh-tui/src/tools/shell.rs.
  • Forbidden tool calls are now blocked even under Yolo approval mode.
  • cosh-cli wrapper tool output is bounded so a chatty subcommand cannot blow the LLM context window.
  • Tool-call IDs synthesized via a process-wide counter to guarantee uniqueness across the agentic loop.
  • settings.json and session files written atomically with 0600 permissions.
  • Runtime bounds enforced for the agentic loop, history, config, and tool messages; scrollback bounded with UTF-8-safe truncation.
  • Panic hook installed in the TUI; history navigation recovered after panic.
  • ws-ckpt IPC response size bounded to 64 MiB.
  • Nonexistent systemd services detected via LoadState=not-found instead of misclassifying them as "inactive".

Security

  • Audit-stub recoverable / hint semantics surface clearly to agents via the standard CoshError envelope.
  • Atomic-rename + 0600 perms on credential-bearing files.

[0.1.0] - 2026-05-10

Initial public-shaped release after renaming the workspace from agos-core to cosh-ng and adding the interactive TUI crate.

Added

  • 4-crate workspace: cosh-types, cosh-platform, cosh-cli, cosh-tui with strict dependency direction cosh-cli / cosh-tuicosh-platformcosh-types.
  • cosh CLI binary with dual-mode dispatch: cosh (no args) execs into cosh-tui, cosh <subsystem> <action> returns structured JSON.
  • Cross-distro pkg subsystem: install / remove / search / list routed across dnf / apt-get (apt-cache for search) / zypper based on Distro::detect() reading /etc/os-release.
  • svc subsystem over systemctl: status / start / stop / restart / enable / disable / list, with uptime and corrected column mapping in list.
  • checkpoint subsystem talking to the ws-ckpt daemon over Unix-socket IPC; bincode wire format with 4-byte LE length prefix and explicit protocol versioning + error handling. Commands: init / create / list / restore / recover / delete / diff / cleanup / status.
  • cosh-tui interactive TUI on ratatui + crossterm: slash-command system with auto-complete, session management, theming, custom border set, echo-on-submit.
  • Agentic loop with cosh-cli wrapper tools in cosh-tui, bringing pkg / svc / checkpoint tooling to the LLM (initially shipped as cosh-tui v0.4.0).
  • LLM chat integration with config-driven providers and UI surfacing.
  • Unified settings.json V2 config consolidating prior scattered config files.
  • AES-256-GCM decryption for encrypted credentials.
  • macOS detection + Homebrew backend in cosh-platform, with unit tests.
  • Unified JSON envelope CoshResponse<T> with ok / data / error / meta, classified CoshError carrying recoverable and hint for agent retry decisions.
  • Integration tests for pkg and checkpoint CLI commands.

Changed

  • Workspace renamed from agos-core (with agos-types / agos-platform / agos-cli) to cosh-ng (with cosh-* crates); agos-cli and agos-platform removed in the same commit.
  • cosh-tui checkpoint tooling adapted to the new daemon protocol.

Fixed

  • cosh-cli stdout validated as JSON before forwarding to the LLM, preventing parser confusion on malformed bytes.

[pre-0.1.0] - 2026-05-03 → 2026-05-08

Pre-rename agos-core foundation.

Added

  • Initial 2-crate workspace agos-types + agos-platform.
  • agos-cli cross-distro CLI prototype with pkg, svc, checkpoint, audit command shapes.
  • MVP v2 CLI Gateway architecture document and bilingual (English / Chinese) usage guide.

Changelog

All notable changes to ktuner are documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

Added

  • Initial kernel-tuning engine: check/tune/fix/why/rollback commands evaluate 207 rules and output structured JSON tuning recommendations.

Changelog

0.6.2

  • Added the ktuner skill for deterministic kernel diagnosis, tuning, and rollback. (#1278)
  • Removed legacy OpenClaw and Hermes adapter scripts from source and RPM installs. (#1172)
  • Updated anolisa-guide with authenticated Skill Ledger recovery and tamper detection. (#2185)

0.6.1

  • Rewrote sysom-diagnosis skill and removed legacy CLI. (#1241)
  • Fixed OpenClaw gateway write scope verification in install-openclaw skill. (#1205)

0.6.0

  • Added anolisa component contract (component.toml, Makefile, RPM spec). (#1159)
  • Added OpenClaw bootstrap guidance to install-openclaw skill. (#1051)
  • Added model endpoint preflight before gateway startup in install-openclaw skill. (#1031)
  • Added static knowledge base update script for anolisa-guide skill. (#1010)
  • Added anolisa-guide skill. (#849)
  • Fixed Aliyun mirror fallback for uv and qwenpaw install. (#968)
  • Fixed dashscope proxy URL to new Anthropic endpoint in install-claude-code skill. (#858)
  • Renamed copaw to qwenpaw across os-skills. (#968)

0.5.0

  • Added anolisa-register skill. (#829)

0.4.0

  • Added auto-install tokenless plugin support for agent install skills. (#731)
  • Added OpenClaw dependency precheck. (#719)
  • Improved OpenClaw non-interactive setup. (#687)
  • Added Hermes adapter runner. (#617)
  • Added standalone ANOLISA adapter entry. (#549)
  • Fixed OpenClaw state dir handling normalization. (#641)
  • Improved Makefile install paths and contract. (#541)

0.3.0

  • Added hermes-agent-install skill. (#353)
  • Added clawhub-skill-mng skill with npm install support and YAML description matching. (#315)
  • Fixed AgentSight custom db path issue, using default paths instead. (#366)
  • Fixed AgentSight token savings query support. (#355)
  • Fixed AgentSight interruption CLI and aligned conversation_id naming. (#334)

0.2.2

  • Support enable AgentSight dashboard in agentsight skill. (#222)

0.2.1

  • Upgraded xlsx skill with MiniMax open-source implementation. (#218)
  • Updated skill descriptions from "suitable for alinux4" to "rpm-base linux". (#182)

0.2

  • Added humanizer, image-gen, pdf-reader, and xlsx skills. (#178)
  • Added cosh-guide skill. (#23)
  • Support net/io/load diagnostic capabilities to sysom-diagnosis skill. (#163)

Changelog

All notable changes to SkillFS are documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

[0.4.0] - 2026-07-24

Added

  • Configurable read-time transforms now keep directive compilation enabled by default and add an opt-in OS adapter with bundled Ubuntu/Alinux rules and external catalog overrides (#1484).
  • An authenticated live-source resolver and notify v2 protocol now give Skill Ledger canonical flat or Hermes skill identities, event kinds, and changed paths without exposing backing-root details (#1517).

Changed

  • Agent-visible access checks now follow activated snapshot permissions while live-source permissions continue to govern writes (#1517).

Fixed

  • SLS telemetry writers now honor /etc/anolisa/.telemetry_disabled dynamically and fail closed when the gate cannot be inspected (#1584).
  • Hermes symlink boundaries, resolver paths, socket ownership, and peer authentication now fail closed across discovery, reads, and mutations (#1517).
  • Control-socket prerequisite diagnostics now consistently include the public --control-socket flag name (#1739).

[0.3.4] - 2026-07-16

Fixed

  • SLS ops logging now preserves exactly one command record when CLI output pipes close early and panic unwinds.

[0.3.3] - 2026-07-10

Added

  • Hermes workspace layout compatibility. SkillFS now recognizes Hermes hub markers, preserves management paths, and exposes nested category/skill/SKILL.md skills alongside top-level skills.
  • Nested Hermes skills now support activation state, installer lifecycle writes, notifications, audit attribution, fallback snapshots, and hidden visibility.

Fixed

  • skillfs validate --json now includes source paths for warning and error entries so automation can locate invalid skills.
  • FUSE teardown now bounds failed unmount cleanup and prevents leaked test mounts from affecting later sessions.

[0.3.2] - 2026-07-03

Fixed

  • CLI SLS ops logging now records SkillFS mount and runtime operations.
  • Runtime metrics now emit real-time deltas for SLS consumers.

[0.3.1] - 2026-07-03

Added

  • Managed mount supervision can recover stale FUSE mounts and bound recovery retries during repeated starts.

Changed

  • English and Chinese README guidance now covers managed mounts, in-place operation, security boundaries, and troubleshooting.

Fixed

  • Post-publish grace reads fallback skill files from source paths after installers finish.
  • skillfs validate now reports parse failures in the status summary.
  • In-place authoring supports new skills and pending-install ownership changes.
  • Managed stop and runtime-dir handling avoid stale ownership and unbounded recovery retries.
  • Daemon-facing backing roots under PrivateTmp are rejected before mount startup.
  • FUSE smoke cleanup handles leftover mounts and temporary paths more reliably.

[0.3.0] - 2026-06-26

Added

  • Runtime security integration for agent skill directories. SkillFS can now consume activation decisions from .skill-meta/activation.json or the user.agent_sec.skill_ledger.activation xattr, then expose each skill as current, hidden, or a trusted fallback snapshot.
  • File-change notification for external security daemons. With --activation-mode file, --notify-socket, --activation-events-log, and --activation-reload-mode poll, SkillFS reports skill mutations, reloads activation decisions, and keeps already-opened file handles pinned to their original target.
  • Trusted control socket for activation writes. A daemon verified with SO_PEERCRED, executable identity, and start-time checks can update activation JSON or activation xattr through a bounded request API instead of writing .skill-meta through the agent-visible mount path.
  • Installer compatibility for common skill installation flows. Staging directories, direct writes, quiet-timeout completion, and post-publish grace windows allow installers to finish writing a skill before SkillFS asks the security provider to scan and activate it.
  • In-place mount support for security daemons. Ledger backing roots are bind mounted privately and validated at startup so scanners read the real source tree rather than the agent-facing FUSE view.
  • Canonical skill identity based on the directory basename. Frontmatter name: remains display metadata and no longer changes the SkillFS store key or daemon-facing skill id.

Changed

  • .skill-meta/** is hidden from ordinary agents and remains accessible only through trusted metadata paths or the control socket.
  • Skill mutation notify uses ordinary filesystem event kinds, including create, write, rename, unlink, rmdir, and truncate events, instead of a separate install-complete protocol event.
  • POSIX passthrough behavior was expanded for symlink, hardlink, FIFO, path length fallback, open-after-unlink, xattr, and inode consistency cases.

Fixed

  • Prevented stale activation views by combining notify-triggered reload, polling, and activation watcher convergence.
  • Hardened trusted-writer and trusted-peer checks against process reuse and executable replacement with start-time and file-identity validation.
  • Avoided installer and daemon visibility bugs around hidden skills, fallback snapshots, staging paths, and backing-root propagation.

[0.2.0] - 2026-05-09

Added

  • FUSE write passthrough for write, create, mkdir, rename, unlink, rmdir, and setattr(size) operations on skill directories.
  • Background sync worker that reparses SKILL.md on write and upserts the entry back into SharedSkillStore.
  • Immediate visibility for newly created skill directories: mkdir inserts a ParseStatus::Degraded placeholder, then the sync worker overwrites it with the real entry once SKILL.md is written.
  • in-place mount mode that accesses the underlying source via /proc/self/fd/{n} to avoid the over-mount self-loop.
  • Integration suite crates/skillfs-fuse/tests/write_guard_tests.rs covering both normal and in-place write paths.

Changed

  • Directory name is now the authoritative store key. After rename, stale frontmatter name: no longer revives the old key.
  • Read of SKILL.md still returns the compiled result; raw file is only used for writes and parsing.
  • Architecture docs refactored into docs/specs/skillfs-spec.md, docs/specs/core-spec.md, docs/specs/fuse-spec.md.

Removed

  • Workspace-related code paths and the unused workspace config support from skillfs-core (commit 6d604c7).
  • Legacy ad-hoc test scripts (kept only scripts/build.sh and scripts/test.sh).

Fixed

  • CLI tracing timestamps now use the local timezone instead of UTC.

[0.1.2] - 2026-04-29

Added

  • Read-only mount write protection: mknod, symlink, link, and write callbacks all return EROFS.

Fixed

  • Parser summary truncation now respects multi-byte character boundaries.

[0.1.1] - 2026-04-29

Added

  • skillfs-mount agent skill under docs/skills/ to help users set up, mount, and unmount a SkillFS instance.

[0.1.0] - 2026-04-25

Added

  • Initial release of the SkillFS workspace.
  • skillfs-core: SKILL.md parser (with Ok / Degraded / Error status), in-memory SkillStore with flat and categorized directory layouts, skillfs-views.toml configuration, conditional compiler::compile, and environment probing (OS, commands, env vars).
  • skillfs-fuse: read-only FUSE filesystem that exposes the configured default view at /skills, always-on virtual skill-discover, and compile-on-read for SKILL.md. Other files in a skill directory are passed through to the physical source.
  • skillfs CLI: mount, classify, validate, list subcommands.

更新日志

Tokenless 的所有重要变更都会记录在此文件中。

从 0.7.2 版本开始,发布记录遵循 Keep a Changelog 格式。

未发布

0.7.5 - 2026-08-10

新增

  • OpenCode 用户现在可以通过无冲突的本地 Plugin 启用 Tokenless,并复用现有的就绪检查、命令重写、Schema 压缩和响应压缩 Hook(1233cfcf)。

变更

  • Qoder Adapter 现在使用原生 Plugin 和 Hook 约定,在保持 fail-open 行为的同时原位替换压缩后的 Tool Output(13817938)。

修复

  • 重写后的 Shell 命令现在使用解析出的 rtk 绝对路径,因此在 PATH 受限的 Agent 环境中仍可正常执行(ae83f7d3)。
  • Qoder 和 OpenClaw Hook 现在会跨命令重写与 Proxy 边界保留 Agent、Session 和 Tool 归因信息(#21582f330656)。
  • Adapter 安装现在可识别旧版 /usr/local 布局、推荐使用 RPM 升级模式,并在升级时删除过期的已打包用户手册文件(f7ce3878ec25d516917f151e)。

0.7.4 - 2026-07-31

新增

  • Tokenless 现在可通过 npm 安装到 Linux 和 macOS x64/arm64,并包含 tokenlessrtktoon 二进制文件以及 Framework Adapter(#1929)。
  • tokenless stats diff 现在可通过文本或 JSON 报告以及有界 Unified Diff,说明 Record、Session 和 Tool Use 的预计节省量(#1991)。
  • TOKENLESS_DATA_DIR 现在可为统计数据库和可逆压缩数据库设置一个可信目录,同时保留各数据库的独立覆盖项(#2038)。

修复

  • Qwencode Adapter 现在声明其提供的 compress-toon Capability,使 Adapter 发现结果与其压缩行为保持一致(#1945)。
  • Hermes 副本安装现在可从可信的系统、XDG 和用户数据路径解析共享 Hook 资源,并在找不到安全候选路径时提供可操作的诊断信息(#2058)。

0.7.3 - 2026-07-28

新增

  • ANOLISA 现在可在 macOS 上安装 Tokenless,并将 Qwencode 作为独立 Adapter 启用(#1964)。

变更

  • Adapter Hook 现在可在用户、/usr/local、RPM 和旧版安装布局中发现 tokenlessrtktoon#1957)。
  • Hook Launcher 现在优先使用当前安装中的资源,避免多个 Tokenless 安装共存时混用不同版本(#1964)。

修复

  • Tool Schema 压缩现在读取 Cosh 和 Cosh-NG 的规范请求字段,因此 Schema 会被压缩,而不再静默原样通过(#1894)。
  • 存在 Hook 环境变量时,Cosh-NG 压缩统计现在归因到 cosh-ng#1894)。
  • Qoder Plugin 安装现在展开缓存的 Hook 路径,避免无效的 /rewrite_hook.py 命令阻塞 Tool Call;用户手册也包含受影响升级的恢复步骤(#1924)。
  • ANOLISA Package 现在包含 Tokenless Adapter 所需的共享 Hook 资源(#1964)。

0.7.2 - 2026-07-27

新增

  • Tokenless 现在通过替换原有 Model 可见内容来压缩 Cosh-NG Tool Response(#1669)。
  • Tokenless 现在可重写受支持的 Cosh-NG Shell 命令,以生成更紧凑的输出(#1669)。

变更

  • Shell 环境检查现在只报告当前命令引用的推荐工具(#1598)。
  • tokenless env-check --fix 现在只安装必需依赖,不会修改可选推荐项(#1598)。
  • 自动依赖修复现在会针对认证、网络或权限问题快速失败并提供可操作信息,而不再提示输入 sudo(#1598)。
  • Cosh-NG 压缩统计现在记录在 cosh-ng Agent 下(#1669)。
  • Cosh-NG 压缩现在从 Model Context 中排除仅供显示的内容(#1669)。
  • 无法检测版本的 Cosh-NG 运行现在会保持原始 Tool Response 不变(#1669)。
  • 压缩结果不够小时,Tokenless 现在会保持 Tool Result 不变(#1674)。
  • Tokenless 用户手册现在位于 ANOLISA 中央指南中,而不再随 RPM Package 提供(#1586)。

修复

  • Claude Code 2.1.121 及更高版本现在会用压缩结果替换原始 Tool Result,避免 Context 重复(#1674#1686)。
  • 较旧或无法检测版本的 Claude Code 现在会原样传递 Tool Result,不再复制压缩后的 Context(#1674#1686)。
  • Claude Code 替换现在会保留内置 Tool Result 格式,包括空字段(#1674#1686)。
  • ANOLISA 现在可以正确识别已打包的 Tokenless 版本(#1587)。

0.7.1

  • 修复 RPM Tarball,使其排除生成的 .anolisa/component.toml,确保 rpmbuild 始终从权威 .toml.in Template 重新生成 Adapter Contract;此前签入的过期副本会缺少 claude-code、codex 和 cosh Adapter 声明(关闭 #1470)
  • 同步 Adapter Contract:在 component.toml.in 中声明所有已交付 Driver(qoder、claude-code、codex、cosh、qwencode),并增加 CI 检查 check-component-contract 以保持同步
  • 将测试覆盖率从 75% 提高到 90%:为四个 Crate 增加约 170 个单元测试,覆盖压缩边界情况、Stash 往返、Schema Migration、SLS Writer 和 CLI Dispatch
  • 强化测试隔离:使用 RAII TempDbGuard / EnvGuard 替换不安全的环境变量修改,避免测试接触真实的 ~/.tokenless 状态;在 Makefile 中强制使用 --test-threads=1(Rust 2024 的 set_var 是 unsafe)

0.7.0

  • 增加 MCP tokenless_retrieve stdio Server(tokenless mcp serve),使连接 MCP 的 Agent 可按需恢复截断 Payload;这是 tokenless retrieve CLI 的 MCP 对应实现,补齐与 Headroom CCR headroom_retrieve 的 Stash MCP 差距
  • 完成其余有损路径的可逆压缩(Stash / CCR)覆盖:ResponseCompressor 字符串截断、ResponseCompressor 深度截断和 SchemaCompressor 描述截断现在都由 Stash 支持并使用 <<tokenless:KEY>> Marker;写入 Stash 前进行容量检查以避免孤立条目,共享的 stash_suffix() Helper 保持 Marker 预算一致
  • compress-schema 增加 --no-stash / --stash-db Flag(与 compress-response 一致);Dry Run(compression_on=false)会跳过 Stash,确保没有可检索条目时 Marker 不会进入 LLM
  • SqliteStore 增加惰性 TTL 清理:在 Retrieve 查询前物理删除过期行,避免 Stash DB 无限增长
  • 增加实际节省率展示:StatsSummary::actual_savings_percent(session_total_tokens)format_summary() / format_summary_json() 接受可选的 Session 总量,并输出“Overall Savings vs Total Consumption”区段及新的 JSON 字段(session_total_tokensactual_savings_tokensactual_savings_percent);未提供时保持向后兼容
  • 为压缩统计增加 Stash 写入与大小计数器(扩展 record_compression_stats);Retrieve 端的命中/未命中统计延后到出现明确使用场景时实现
  • 增加 Qoder Framework Driver(qodercli 安装、settings.json Merge/Prune、AdapterOps::read_file、Symlink-safe 原子 write_file);仅允许 Qoder 使用 adapter_type=plugin;对伪造 Receipt fail closed,并要求所有受管 Hook 存在
  • 将测试覆盖率从 59% 提高到 75%:四个 Crate 新增 100 多个单元测试和 18 个 CLI 集成测试;测试代码通过 include!() 移至 src/tests/,使代码结构更清晰
  • 增加可逆压缩用户手册(docs/stash-reversible-compression.md)并更新 README:为 tokenless-ccr 增加架构树条目,增加说明 Hash/Marker 输入和 --no-stash / --stash-db 的 Retrieve 小节,并按场景映射重写“适用场景与预期效果”章节
  • 将 Tokenless 文档从 *_CN.md 重命名为 *_zh.md,增加双向双语链接,并创建 README.mdREADME_zh.md
  • 处理 Adapter Review 发现:信任 Codex Symlink Target 的已打包数据目录 Root;按组件限定 Claude Code Marketplace 并 fail closed;启用前拒绝 Framework/Adapter Type 不匹配
  • 消除 rustc 1.94 stable 在现有测试中发现的 Clippy Warning(tokenless-cli 中的 field_reassign_with_default,tokenless-stats 中的 bool_assert_comparisondefault_constructed_unit_structs

0.6.1

  • 将 tool_categories.json 打包进 dist,用于 npm 安装
  • 使用 node: Prefix,并在 OpenClaw Plugin 中移除 Shell Subprocess

0.6.0

  • 在 JSON 输出中增加绝对保存值和 Schema Version
  • 在 OpenClaw Plugin 中使用 import.meta.dirname 替代 __dirname
  • 为 Qwen Code Extension 增加 Qwencode Adapter
  • 修复 RTK pytest 的“No tests collected”回归
  • 为 Codex Script 中的 hook_utils Import 增加可信 FHS Fallback Path
  • 增加带配置开关的 SLS JSONL 数据收集
  • 增加 Tokenless RPM Component Contract(发布元数据)
  • 增加带 Dry-run 比较模式的压缩开关(TOKENLESS_COMPRESSION_ENABLEDstats summary --compare
  • 默认启用 SLS 记录并补充使用文档
  • 对齐压缩模式的 Serde/DB 形式并去重配置加载
  • 扩展 RPM Component Contract(bundle.entry + hermes)
  • 将 SLS Writer 改为仅追加,并在日志文件不存在时跳过
  • Qwencode Hook 优先使用 tool_call_id,而不是内部 tool_use_id
  • 将 Vendored RTK 升级至 v0.43.0;针对重构后的 Runner 重做 pytest stderr 输出 Patch;删除 grep-fallback-fix(上游已修复根因)和 preflight-skip-python(上游已撤销)
  • 将 Makefile 和 Spec 中的 toon-format 同步到 0.5.0(此前仍为 0.4.6)

0.5.1

  • stats summary 增加 --json 输出
  • 实现统一 Tool 分类和三层压缩策略
  • 增加 RTK grep Fallback Pattern 修复 Patch
  • 增加 RTK pytest Error Report Patch

0.5.0

  • 增加 Hermes Adapter Runner
  • 移除 TOON Wrapper Prefix 并精简诊断 Tag
  • 在各 Adapter 中统一 RTK Rewrite Exit Code 3 的处理
  • 保护 env-fix 和 Hook 中的 Shell 变量插值
  • 增加 Subprocess Return Code 检查,并提取共享 Hook Utility
  • 保护 resolveBinaryPath 并改进 Binary Cache 失效逻辑
  • 在测试中使用 mktemp 和安全的 Home 展开
  • 限制 SchemaCompressor 递归深度,防止 Stack Overflow
  • 传播 env-fix Subprocess Failure,不再只返回 stdout
  • 基于 getpwuid_r 进行 Home 查询,并对候选 Binary 执行 Trust Check
  • 使用 UID Trust Check 强化 env-fix 安装路径,并将 stderr 转存到日志
  • Stats Recorder 从 Poisoned Mutex 恢复,不再直接失败
  • 增加输入大小限制并校验 DB Path
  • 在 Response Compressor 中预留 Truncation Marker 长度
  • 将 OpenClaw Plugin Name 重命名为 Tokenless,ID 重命名为 tokenless
  • 增加 Qoder CLI Adapter
  • 支持对 Array Input 执行 compress-schema
  • 压缩被跳过时发出警告
  • 增加 Stats Command Syntax
  • 增加 Claude Code Adapter Plugin
  • TTY stdin 输入时返回错误,不再挂起
  • 增加 Codex Adapter Plugin
  • 修复压缩 Pipeline 的输出膨胀、截断和 Hook Timeout
  • 强化 env-fix、版本提取、文件信任、Schema 和权限
  • 处理 Review 发现:Trailing Newline、chmod Guard、Rate-limited Log 和 Comment
  • 使 skip-tools 条目可进行环境归因
  • 增加 selective-claw Context Engine Plugin
  • 处理 selective-claw Plugin Review 发现
  • 从 selective-claw 中移除无效的 2 依赖
  • 恢复 compress_response_hook.py 中的缩进
  • 强化 Hook Exit Code 处理和 Trust Model 一致性
  • 只对真正异常的 RTK Exit Code 发出警告
  • 去重 rewrite_hook,并从 hook_utils 导入

0.4.1

  • 修复 env_check.rs 中 version_ge 的三段版本截断问题(比较所有分段)
  • 增加 Qoder、Claude Code、Codex Adapter Plugin 和文档
  • 将 manifest.json 与 Template 同步,以包含全部六个 Agent
  • 更新 README 和用户手册,记录新的 Agent Integration
  • pycache 加入根 .gitignore
  • 更新 response-compression.md,记录全部 Agent Integration Path
  • 从 Cargo.toml 派生 Makefile 版本,并修复 Spec Changelog 的星期
  • 将 Adapter 版本号统一为 0.4.0
  • 从 Cargo.toml 派生 Adapter Plugin 版本,不再硬编码

0.4.0

  • 修复 Stats、命名、SQL、路径和权限中的 5 个 Bug
  • 对齐 FHS 路径、重构 Adapter 目录并移除 install.sh
  • 处理 Schema、env-check、Hook 和 Plugin 中的 Code Review 发现
  • 增加 Hermes Agent Plugin
  • 强化安全性并修复关键算法正确性
  • 修复行为正确性和逻辑问题
  • 去重、删除 Dead Code 并进行表面清理
  • 支持 Staged Install
  • 支持 Debian/Ubuntu FHS 路径并强化 Binary Resolution
  • 将 OpenClaw Plugin 构建到 dist/index.js

0.3.2

  • 使用 libc::getuid() Syscall 替换可伪造的 Home Directory UID 推导,保证 Trust Chain 完整性
  • 使用进程内 toon_format::encode_default() Library Call 替换 Subprocess toon -e 调用
  • 使用 crates.io Dependency 和内联 toon-format Source 替换 RTK/TOON Git Submodule
  • justfile 的 setup-rtk Recipe 在 RTK Stats Patch 失败时 Hard Fail
  • 统一 compress-toon、compress-schema 和 compress-response 的 Error Exit Code(均为 2)
  • 从 Makefile 的 toon 安装中移除 2>/dev/null || true(Binary 缺失时 Hard Fail)
  • 删除已具有 #[from] 的 thiserror Variant 上多余的 #[source] Attribute
  • 将 Python Hook 的 FHS Path Constant 去重到共享 hook_utils Module
  • 将 libc 加入 Workspace Dependency,用于 UID Syscall
  • 在 spec.in 中增加 rust >= 1.89 的详细注释,说明 CI Pin 的原因

0.3.0

  • 增加与 Cosh Extension 集成的 Tool-ready 四阶段环境预检查
  • 无 Token 节省时跳过压缩和统计
  • 通过 .rewrite-context 文件向 RTK Stats 传递 Caller Context
  • 从 install.sh 中移除多余的 Cosh Extension 安装/卸载
  • 按 Cosh 开发指南将 Cosh Hook 转换为 Extension 格式
  • 跳过零压缩和统计记录
  • 在 OpenClaw Plugin 中使用 isExecutable() 和解析后的路径
  • 为 RPM 安装的 Plugin 解析 RTK/TOON Binary Path
  • 修正 RPM 安装路径,使其符合 install.sh 预期
  • 在 TOON Encoding 中保留 Tool Result Message 结构
  • 将安装路径与 FHS 对齐
  • 使用 Hook Payload 中真实的 tool_use_id 自动记录 Stats
  • 重构 RPM 目录并移除自动 Plugin/Hook 安装

0.2.0

  • 增加基于真实数据自动记录的压缩统计
  • 增加 TOON Context 压缩支持
  • 对 Skill 和内容检索 Tool 跳过压缩

0.1.0

  • 将 Tokenless 引入 ANOLISA(#199)

更新日志

0.4.2

新功能

  • 新增 ops 日志写入的遥测门控 (#1509)

缺陷修复

  • 修复中断 init 后遗留的 .pre-init-bak 自动恢复 (#1601)

0.4.1

新功能

  • 新增 rollback 后跳过自动 checkpoint (#1263)

缺陷修复

  • 修复 config 更新后的工作区同步 (#1263)
  • 修复 crontab 条目中 ws-ckpt 的绝对路径处理 (#1263)
  • 变更 rollback -n 偏移量,直接传递 numAncestors (#1263)

0.4.0

不兼容变更

  • 不兼容 checkpoint -i/--id 参数更名为 -s/--snapshot 作为主参数;-i 保留为隐藏别名,未来版本可能移除 (#1064)

新功能

  • 新增插件安装/卸载子命令 (#1005)
  • 新增 component.toml 用于 anolisa-cli 适配器发现 (#1005)
  • 新增 rollback 预览功能,支持 --preview 参数 (#1103)
  • 新增每次 CLI 操作后的耗时显示 (#1075)
  • 新增省略 --snapshot 时自动生成快照 ID (#1064)
  • 新增 SLS 运维日志输出用于仪表盘指标 (#1059)
  • 新增 diff 的可选 -t 参数,用于将快照与当前工作区对比 (#848)
  • 新增按祖先数量 rollback 和快照 DAG 追踪 (#877)
  • 新增基于 cron 的定时 checkpoint 快照 (#819)

缺陷修复

  • 修复 --snapshot/-s 作为主参数的处理及插件参数对齐 (#1103, #1064)
  • 修复 SKILL.md 与实际 CLI/插件实现的同步 (#847)
  • 修复 init 和 recover 对被替换的 workspace 符号链接的防护 (#860)
  • 修复 init rsync 去除 --copy-unsafe-links (#873)

0.3.3

新功能

  • 新增每工作区策略覆盖,支持 hermes/openclaw 插件 (#721)
  • 新增 /proc cwd 占用者检测,用于 init 和 rollback (#684)
  • 新增 Hermes 适配器运行脚本 (#617)

缺陷修复

  • 修复 rollback 中的写锁竞争和 cwd 检测死锁 (#721, #684)
  • 修复非 UTF-8 路径和路径穿越快照 ID 的输入验证 (#695, #678)
  • 修复 seccomp 架构选择、工作区注册并发和 RPM 打包问题 (#695, #684)

0.3.2

  • 修复 openclaw 卸载时未从配置中移除工具白名单
  • 修复父路径拒绝规则作为工作区级别规则应用于 skill 和 openclaw 插件

0.3.1

  • 修复插件工作区配置注册和自动加载
  • 拒绝将 hermes cwd 本身或其父路径作为工作区路径
  • 修复插件工具优先使用显式 workspace 参数而非配置
  • 修复 skill 删除需要 --force 参数
  • 修复 daemon 工作区路径验证和 fswatch 文件描述符泄漏
  • 移除未使用的 btrfs_ops.rs 模块

0.3.0

  • 新增 openclaw 插件脚手架
  • 新增 hermes 插件脚手架
  • 将 ws-ckpt skill 改为 agent 无关,在调用时提示输入工作区
  • 遵循 make install 契约用于 build-all 集成
  • 修复 list 和 diff 子命令的缺陷
  • 将 daemon 改为有状态

0.2.0

  • 新增 auto_cleanup 功能及开关
  • 统一通过 TOML 文件修改配置
  • 新增全局 CLI 警告:当任意工作区快照数 >1000 或文件系统使用率 >90%
  • 修复后端检测和 daemon 状态恢复逻辑
  • 修复 daemon 重启后镜像大小配置不生效
  • 移除过时的 fs_warn_threshold_percent 参数
  • 修复 config.toml 作为示例文件分发

0.1.0

  • 带 Unix Socket IPC 和 Bincode 二进制协议的 Daemon
  • init / checkpoint / rollback / delete / list / diff / cleanup / status / config 命令
  • 后台调度器:自动清理、健康检查、孤立恢复
  • 多后端:btrfs-base / btrfs-loop / overlayfs 自动检测
  • TOML 配置持久化及运行时热重载
  • systemd 服务及 Alinux 4 RPM 打包