docs: backfill CHANGELOG + docs/releases entries for 0.4.7 / 0.4.8 / 0.5.0

Backfills release-notes documentation for the three published releases
that shipped without an in-repo docs pass:

- docs/releases/v0.4.7.md — recovery honesty + starter bootstrap + skills
  wave + Slack connector + UI maintenance-mode milestone (web UI moved to
  maintenance mode at 0.4.7; CLI/TUI primary from this release forward)
- docs/releases/v0.4.8.md — permission-posture fast-follow + policy-spec
  framework (rig setup --policy flag + harness-neutral spec schema; the
  built-in template files themselves land in 0.5.0)
- docs/releases/v0.5.0.md — mission control TUI + context library +
  permission-policy built-ins (locked/standard/open/yolo/none) +
  applying-a-permission-policy skill + permission-guarantee test-pinned +
  provider usage observability + plan amendment + honest CLI output +
  build discipline

CHANGELOG.md entries added for [0.4.7], [0.4.8], and [0.5.0] with the
same content, prepended above the existing [0.4.6] entry.

Content sourced from the substantive release-commit body prose banked
at cut-time for each ship. No source-code, migration, dependency, or
behavior changes.

Companion to the GitHub Releases created for the same three tags this
session:
- https://github.com/mvschwarz/openrig/releases/tag/v0.4.7
- https://github.com/mvschwarz/openrig/releases/tag/v0.4.8
- https://github.com/mvschwarz/openrig/releases/tag/v0.5.0

Prior gap: tags + npm publish had continued cleanly every cut since
0.4.6, but the CHANGELOG + docs/releases + GitHub Releases surfaces
had fallen behind. This commit closes the CHANGELOG + docs/releases
side; the GitHub Releases side was closed via gh release create
earlier in the session.
This commit is contained in:
mvschwarz
2026-08-07 09:36:49 -07:00
parent 20991e3cc1
commit a310c16171
4 changed files with 575 additions and 0 deletions
+187
View File
@@ -8,6 +8,193 @@ deprecations, and behavioral changes. Breaking changes are called out explicitly
---
## [0.5.0] - 2026-08-06
**Status**: shipped; mission control TUI + context library + permission-policy built-ins + provider usage observability + plan amendment + honest CLI + build discipline. **0.5.0 contains 0.4.8 in full** via the back-merge that reconciles the 0.4.8 release-artifact history with the 0.5.0 working lineage.
### Summary For Installing Agents
- **Package version**: bumps from `0.4.8`.
- **Migrations**: additive only.
- **Node engines**: unchanged.
- **New bundled skills**: `applying-a-permission-policy` and `delegating-work` join the shipped set alongside the 0.4.8 skills. Two additional 0.5.2-lane maturation-gated skills (`retiring-and-inheriting-a-seat` and `oversight-team`) sit in the oracle at draft stage and are correctly deferred to a later release per the maturation-gate contract.
- **Behavior change**: `rig.yaml` startup `context_pack` entries are no longer delivered at instantiation — they are rejected with a teaching error pointing at `rig context compose` + delivery verbs.
### Headline
**Mission control in the terminal + context library + permission-policy built-ins.** Typing `rig` (or `rig tui`) opens the new TUI: file-tree navigator, dense agent detail (cwd, runtime as text, context %), topology graph with the whole fleet on one screen, honest status/activity language, motion design, working scrolling, and honest width-clip/scope indicators throughout. The context library ships as a first-class store-and-compose noun (`rig context`) with paced delivery via `rig walk` and attached-context on `send` / `broadcast` / `queue create` via `--context` / `--body-context`. The 0.4.8 permission-policy framework gets its **five built-in templates** (`locked | standard | open | yolo | none`) + an agent-driven translator skill.
### Permission policies — built-in templates + custom + agent-driven translation
Building on the v0.4.8 policy-spec system, v0.5.0 ships the built-in policy templates + the skill that applies them:
- **Five built-in policy templates**: `locked`, `standard`, `open`, `yolo`, `none`. Read-only from the package; copy to customize.
- **`rig setup --policy <name>`** — records the chosen policy into a rig spec. Takes a built-in name or a path to a custom policy file (`source: custom`).
- **`applying-a-permission-policy` (bundled Tier-A skill)** — reads the policy spec at rig setup / preflight, grounds itself in the seat's current harness version (Claude 2.1.220 / Codex 0.120.0 / Pi 0.83.0 at ship time), shows the concrete diff before writing, and lands the config into Claude `~/.claude/settings.json` and/or Codex `config.toml`. Never blind writes.
- **Two surfaces (unchanged from v0.4.8)** — LAUNCH-FLAG (stable, OpenRig-set deterministically): the FLOOR (Claude `acceptEdits`, Codex workspace-write) and YOLO (Claude `--dangerously-skip-permissions`, Codex full-bypass). CONFIG-FILE (chaotic, translated per harness version by the skill): the allow/ask/deny rules.
- **Deterministic vs best-effort** — LAUNCH-FLAG floor + YOLO are deterministic. Fine-grained CONFIG-FILE rule translation is best-effort; the skill surfaces prefix-collision, target-first leaks, and Claude-only network-egress non-enforceability to the operator honestly via the diff-before-write flow.
### Permission guarantee, now test-pinned
- **OpenRig writes zero permission entries into your `~/.claude/settings.json`** — pinned by a permanent guard test plus an empty-writer sweep. The one sanctioned exception is the project-local `acceptEdits` floor that 0.4.8 itself defines.
- **Warning ordering in `permission-policy-discovery`** — emits pre-existing main-floor warnings first, then the permission-policy attachment warning. Presentation-only; semantic fence unchanged.
### Context library
- **`rig context`** — stores and composes context packs. Nouns store and compose; `rig context` never delivers.
- **`rig walk`** — delivers a stored context pack paced.
- **`--context` / `--body-context`** — attach a stored context pack (by ref) to `rig send`, `rig broadcast`, or `rig queue create`. Snapshot + provenance preserved.
- **Grammar (strict)**: nouns store and compose; verbs deliver. The 0.4.x context-window usage viewer is removed; the `rig context` name now belongs to the library.
### Behavior change (0.4.8 → 0.5.0)
- **`rig.yaml` startup `context_pack` entries are no longer delivered at instantiation.** They are rejected with a teaching error pointing at `rig context compose` + a delivery verb (`rig send --context`, `rig broadcast --context`, `rig walk`, or `--context` / `--body-context` on `queue create`). The bundle router populates the library store without delivering (delivery-free-noun ruling applied at the startup surface). Users who adopted startup `context_pack` on 0.4.8 (shipped days ago; tiny exposure) should migrate to the compose + delivery-verb pattern.
### Provider usage observability
- **`GET /api/provider/usage`** + **`rig provider status`** — the daemon tracks account-level usage per host so operators can answer "am I about to hit a usage limit". Honest explicit-unknown and conflict-shows-both-facts semantics. Codex account-switch flows preserved.
### Plan amendment done right
- **`rig scope slice approve --re-approve --reason "..."`** — re-stamps a locked plan with an append-only audit trail, killing the old `already_approved` Status-note workaround.
### Honest CLI output
- **`rig ps`** — says when it is showing one rig of many rather than silently limiting.
- **`rig send --json`** — returns structured errors as `{fact, consequence, action}`.
- **Activity-hook fix** — ends the fleet-wide "producer link stale" advisories that were firing on every send. Operator-facing quality improvement.
### Build discipline
- **Contributor gates/lanes SSOT** lives at `docs/reference/developing.md` (encoded by the slice-12 gates policy).
### UI status (unchanged from v0.4.7)
- **Web UI remains in maintenance mode** as introduced in v0.4.7 — still ships, still runs, no new feature work. CLI/TUI is the primary surface; v0.5.0's TUI (`rig` / `rig tui`) is where mission-control investment lands. Never "deprecated"; existing deployments continue to work.
### Known Issues
- **GAP-7 Codex-`HOME` product fix** (seal CLEAR `b7f4cb7d`) — accepted with fold-rides-release-sequencing but fell off the fold-wave enumeration and is **NOT in released 0.5.0 by content**. Ships in 0.5.1 as a ready-accepted early bugfix atom. Class: sibling of the slice-03 omission, caught by census not damage. Until 0.5.1 lands, the deployment invariant from v0.4.8 (daemon `HOME` == seat tmux `HOME`) remains the operator-side workaround for the permission-posture writes to reach Codex seats.
---
## [0.4.8] - 2026-08-05
**Status**: shipped; permission-posture fast-follow + permission-policy framework.
### Summary For Installing Agents
- **Package version**: bumps from `0.4.7`.
- **Migrations**: additive only. Existing v0.4.7 databases upgrade by running `rig daemon start` on the new daemon.
- **Node engines**: unchanged.
- **Default launch posture changed**: from hardcoded `--permission-mode acceptEdits` to configurable, default `dontAsk`. If a seat needs the prior behavior, `acceptEdits` remains selectable; a deliberate `bypassPermissions` is preserved untouched across writes.
### Headline
**Permission-posture fast-follow + permission-policy framework.** Launch posture is configurable, the deny set is clobber-resistant, and dangerous ops are bounded by an honest prefix-gate. The **permission-policy spec framework** (harness-neutral schema + `rig setup --policy` flag) lands as the foundation the built-in templates + `applying-a-permission-policy` skill ride on top of in v0.5.0.
### Configurable launch posture
- **`--permission-mode` no longer hardcoded** — replaced by a configurable posture defaulting to `dontAsk`. This kills the ask-hang / freeze class that could park an autonomous seat on a modal permission prompt with nobody to click through it. `dontAsk` is the default because it matches what an autonomous seat can actually respond to; `acceptEdits` remains selectable when a seat needs the prior behavior.
### Clobber-resistant deny set
- **Writes go to user-level `~/.claude/settings.json`** instead of the project-local one-off approval surface — so **deny wins over project-local approvals**. Writes are additive (never destructive to sibling keys) and forward-migrate a legacy `acceptEdits` value into the new schema. A deliberate `bypassPermissions` value is preserved verbatim.
### Bounded-dangerous deny set
- **Four bounded-dangerous ops gated by default**: `git push`, `gh pr create`, `npm publish`, and `rig down`.
- **`rig down` gate via prefix superset `Bash(rig down:*)`** — harness rules at Claude 2.1.220 are prefix-only; flag-only patterns provably fail to gate target-first forms such as `rig down <rig> --force`, which were slipping through. The prefix gate is the only shape that actually holds at this harness version. Plain `rig down` is gated in 0.4.8; selective allowance (e.g. `rig down <rig>` for a specific target) is deferred to 0.5.0 server-side enforcement.
### `rig up` un-gated
- **`rig up`'s prior release ask-gate is superseded** — `rig up` is a reversible op and does not warrant an interactive gate.
### Permission-policy framework (foundation for the 0.5.0 built-ins + skill)
- **Harness-neutral policy schema** — the permission-policy spec ships as a harness-neutral surface with `default_posture`, `floor`, `allow`/`ask`/`deny` as **semantic actions** (`push_to_remote`, `force_push`, `delete_files`, `read_secrets`, `create_pr`, `publish_package`, `mutate_topology`, ...), `destructive_class`, and a `source: builtin|custom` marker.
- **`rig setup --policy <name>`** — new flag on `rig setup` records a deliberate permission-policy choice into an existing rig spec. Takes a built-in name or a path to a custom spec. The **built-in policy files themselves land in v0.5.0**; 0.4.8 ships the framework that consumes them.
- **Two surfaces documented** — LAUNCH-FLAG (Claude `--permission-mode`, Codex sandbox/bypass, Pi `--approve` / `--no-approve`) is stable and OpenRig-set deterministically — this is where the FLOOR and YOLO live. CONFIG-FILE (Claude `~/.claude/settings.json`, Codex `config.toml`) is chaotic across harness versions and translated interactively per harness version by an agent-driven skill (that skill lands as `applying-a-permission-policy` in v0.5.0).
### Deployment Invariant (operators read this)
- **The daemon's `HOME` must equal the seat's tmux `HOME`** for the posture writes to reach seats. This is a 2.1.220 settings-path class invariant that operators need to know for the remote-host leg of any upgrade. Local-only hosts satisfy this automatically; remote-host upgrades should verify HOME parity between the daemon process and the tmux seat process before treating the upgrade as complete. (v0.5.0 documents this as a Known Issue for Codex-`HOME` divergence via GAP-7; the product fix ships in 0.5.1.)
### Superseded / Withdrawn
- **Initial 0.4.8 attempt withdrawn pre-cut on final review** — the initial attempt baked `dontAsk` as a **platform default** across the product surface, which was rejected. The shipped 0.4.8 is a re-scoped permission-agnostic base + policy-spec system. Nothing from the withdrawn attempt shipped.
---
## [0.4.7] - 2026-08-03
**Status**: shipped; recovery honesty + starter bootstrap + skills wave + Slack connector + UI maintenance-mode.
### Summary For Installing Agents
- **Package version**: bumps from `0.4.6`.
- **Migrations**: additive only. Existing v0.4.6 databases upgrade by running `rig daemon start` on the new daemon.
- **Node engines**: unchanged.
- **Rig-spec starter behavior change**: rigs instantiated before 0.4.7 need re-instantiation (or spec-level patching) to pick up the starter fixes — the loader and audit changes apply immediately, but starter-spec content lands at instantiation.
- **Web UI**: frozen in maintenance mode at this release (see below).
### Headline
**Recovery honesty is the through-line.** On a resumed restore, the startup orchestrator now bundles the applicable `after_ready` `send_text` preload action(s) in front of the first `send_text` post-launch file (`role.md`) and delivers them as the single leading turn — sequencing (not timing) guarantees the "load skills before doing anything" preload precedes the role-triggered first turn (the restore analogue of `deliverInitialSessionPrompt`'s fresh identity+`role.md` bundle). Compaction recovery and transcript ingest are honest; daemon liveness reporting is honest; CLI probes report uncertainty honestly. Alongside recovery, the release lands starter bootstrap hygiene, a broad skills-inventory wave, a first-class Slack connector, tightened CLI contract honesty, and the **UI maintenance-mode milestone** (CLI is primary from here forward).
### Recovery honesty
- **Startup orchestrator preload bundling** — on a resumed restore, applicable `after_ready` `send_text` preload actions are bundled in front of the first `send_text` post-launch file (`role.md`) and delivered as the single leading turn. Sequencing guarantees the "load skills before doing anything" preload precedes the role-triggered first turn.
- **Claude transcript ingest** — fixed with explicit degraded signals so a stale capture no longer looks like a quiet transcript.
- **Post-compact restore/audit is idle-gated** — restore-sent actually means delivered.
- **Seat liveness API** — consumers should key seat liveness off `lifecycleState` (honest ~3s) rather than `sessionStatus` (staleness cleanup tracked for a subsequent release).
- **Daemon `rig ps` + daemon-status** — report liveness honestly: a dead tmux seat drops effective running to 0 with `attention_required`; `send` and `capture` return `session_missing` when the seat is gone.
- **CLI probes report uncertainty honestly** — unconfirmable status returns `UNKNOWN` with no false start advice; confirmed-stopped still `FAIL`s with guidance.
### Starter bootstrap
- **Product-team starter bootstrap hygiene** — plus product-team `send_text` skill-preload on `fresh_start` and `restore`.
- **Default culture loads at startup** — rig specs are audited at load time.
- **Rig-spec migration path** — rigs instantiated before 0.4.7 need re-instantiation (or spec-level patching) to pick up the starter fixes; loader and audit changes apply immediately, but starter-spec content lands at instantiation.
### Skills wave
- **Bundled skill layer** — gains public routing + a default projection, plus public-skill strip and mirror controls, plus a plugin fix that keeps the documented skill count honest.
- **Vendored skill inventory** — canonical, shared, and bundled plugin — grows from a handful to broad coverage across core, PM, pod, and process families.
### Slack connector + human queue
- **First-class Slack connector shape** — CLI `commands/slack.ts` + supporting library. Hosted create crosses an inconclusive local probe to the real configured-daemon result.
### CLI contract honesty
- **`--json` errors, flag validation, and scoped overdue behavior** tightened for machine-readable use.
### UI — moved to maintenance mode (milestone)
- **The web UI is frozen at this release in maintenance mode.** Wording is CLI-primary — never "deprecated". The UI still ships and still runs; it is no longer receiving new feature work. CLI/TUI is the primary surface going forward.
- What lands in 0.4.7 to make this explicit:
- A dismissible in-app banner in the web UI announcing the maintenance-mode status.
- A `rig ui open` stderr notice at launch time, so operators driving the CLI see the status before they open the browser.
- Documentation positioning updated across README / user-facing docs.
- Existing 0.4.6 deployments keep working; nothing is removed. The substantive product investment shifts to the CLI and, from v0.5.0, the terminal TUI.
### Queue, topology, review polish
- **Queue compact-list rows** mark elided fields so *omitted* is not *empty*.
- **Nested Approve** posts a missions-root-relative `scopePath`.
- **Mission review card composition** is polished.
- **Unverified delivered items** read `artifact-recorded` rather than "nothing delivered".
- **Drawer `FileViewer`** resolves inline C1-body images via `/api/files/asset`.
- **Proof-of-work Markdown links** open in the in-app drawer.
- **Docs guard** encodes the ratified `docs/DESIGN.md` root placement.
### Host sizing guidance
- **Swap + per-box seat budget** — add swap and a sane per-box seat budget (~2GB RSS per seat observed baseline).
---
## [0.4.6] - 2026-07-09
**Status**: shipped; workflows + multi-host coordination + factory foundations theme. 0.4.5 was skipped (no cut).
+107
View File
@@ -0,0 +1,107 @@
# OpenRig v0.4.7
> **⚠️ Milestone:** v0.4.7 is where the **web UI moves to maintenance mode**. The CLI is the primary product surface from this release forward; the web UI still ships and still works, but is no longer receiving new feature work. If you drive OpenRig from a browser today, plan a transition to the CLI (and, from v0.5.0 onward, the terminal TUI: `rig` / `rig tui`). See the UI section below for the specifics that ship in 0.4.7.
## Summary — Recovery honesty + starter bootstrap + skills wave + Slack connector + UI maintenance-mode
Recovery honesty is the through-line. On a resumed restore, the startup
orchestrator now bundles the applicable `after_ready` `send_text` preload
action(s) in front of the first `send_text` post-launch file (`role.md`) and
delivers them as the single leading turn — sequencing (not timing) guarantees
the "load skills before doing anything" preload precedes the role-triggered
first turn (the restore analogue of `deliverInitialSessionPrompt`'s fresh
identity+`role.md` bundle). Compaction recovery and transcript ingest are
honest: Claude transcript ingest is fixed with explicit degraded signals; a
post-compact restore/audit is idle-gated so restore-sent actually means
delivered. Consumers should key seat liveness off `lifecycleState` (honest
~3s) rather than `sessionStatus` (staleness cleanup tracked for a subsequent
release). Daemon `rig ps` and daemon-status report liveness honestly — a
dead tmux seat drops effective running to 0 with `attention_required`; `send`
and `capture` return `session_missing` when the seat is gone. CLI probes
report uncertainty honestly — unconfirmable status returns `UNKNOWN` with no
false start advice, and confirmed-stopped still `FAIL`s with guidance.
Migrations are additive only. Existing v0.4.6 databases upgrade by running
`rig daemon start` on the new daemon.
## What Shipped
### Starter bootstrap
Product-team starter bootstrap hygiene, plus product-team `send_text` skill-
preload on `fresh_start` and `restore`. Default culture loads at startup, and
rig specs are audited at load time. Rigs instantiated **before** 0.4.7 need
re-instantiation (or spec-level patching) to pick up the starter fixes — the
loader and audit changes apply immediately, but starter-spec content lands
at instantiation.
### Skills wave
The bundled skill layer gains public routing + a default projection, plus
public-skill strip and mirror controls, plus a plugin fix that keeps the
documented skill count honest. The vendored skill inventory (canonical,
shared, and bundled plugin) grows from a handful to broad coverage across
core, PM, pod, and process families.
### Slack connector + human queue
First-class connector shape (CLI `commands/slack.ts` + supporting library),
with hosted create crossing an inconclusive local probe to the real
configured-daemon result.
### CLI contract honesty
`--json` errors, flag validation, and scoped overdue behavior tightened for
machine-readable use.
### UI — moved to maintenance mode
**The web UI is frozen at this release in maintenance mode.** The wording
is CLI-primary — never "deprecated"; the UI still ships and still runs,
but it is no longer receiving new feature work, and CLI/TUI is the primary
surface going forward. What lands in 0.4.7 to make this explicit to users:
- A dismissible in-app banner in the web UI announcing the maintenance-
mode status.
- A `rig ui open` stderr notice at launch time, so operators driving the
CLI see the status before they open the browser.
- Documentation positioning updated across README / user-facing docs.
Existing 0.4.6 deployments keep working; nothing is removed. The
substantive product investment shifts to the CLI and, from v0.5.0, the
terminal TUI.
### Queue, topology, review polish
Queue compact-list rows mark elided fields so *omitted* is not *empty*;
nested Approve posts a missions-root-relative `scopePath`; mission review
card composition is polished; unverified delivered items read
`artifact-recorded` rather than "nothing delivered"; drawer `FileViewer`
resolves inline C1-body images via `/api/files/asset`; proof-of-work
Markdown links open in the in-app drawer; docs guard encodes the ratified
`docs/DESIGN.md` root placement.
### Host sizing guidance
Add swap and a sane per-box seat budget (~2GB RSS per seat observed
baseline).
## Behavior + Compatibility
- **Migrations** — additive only. Existing v0.4.6 databases upgrade by
running `rig daemon start` on the new daemon.
- **Rig-spec starter behavior** — the loader + audit changes apply
immediately; starter-spec content lands at rig instantiation. Rigs
instantiated before 0.4.7 need re-instantiation (or spec-level
patching) to pick up the starter fixes.
- **Seat-liveness API** — consumers should key seat liveness off
`lifecycleState` (honest ~3s) rather than `sessionStatus` (staleness
cleanup tracked for a subsequent release).
- **Web UI posture** — frozen in maintenance mode; no CLI surface
breakage. Nothing is removed from the UI at this release.
## See Also
- `CHANGELOG.md` — the `[0.4.7]` entry.
- `docs/releases/v0.4.6.md` — the prior release (workflows + multi-host + factory).
- GitHub Release: https://github.com/mvschwarz/openrig/releases/tag/v0.4.7
+104
View File
@@ -0,0 +1,104 @@
# OpenRig v0.4.8
## Summary — Permission-posture fast-follow
Launch posture is configurable, the deny set is clobber-resistant, and
dangerous ops are bounded by an honest prefix-gate.
Migrations are additive only. Existing v0.4.7 databases upgrade by running
`rig daemon start` on the new daemon.
## What Shipped
### Configurable launch posture
The hardcoded `--permission-mode acceptEdits` launch flag is replaced by a
configurable posture defaulting to `dontAsk`. This kills the ask-hang /
freeze class that could park an autonomous seat on a modal permission
prompt with nobody to click through it. `dontAsk` is the default because
it matches what an autonomous seat can actually respond to; `acceptEdits`
remains selectable when a seat needs the prior behavior; a deliberate
`bypassPermissions` is preserved untouched across writes.
### Clobber-resistant deny set
The posture writes to user-level `~/.claude/settings.json` instead of the
project-local one-off approval surface, so **deny wins over project-local
approvals**. Writes are additive (never destructive to sibling keys) and
forward-migrate a legacy `acceptEdits` value into the new schema. A
deliberate `bypassPermissions` value is preserved verbatim.
### Bounded-dangerous deny set
`git push`, `gh pr create`, `npm publish`, and `rig down` are the four
bounded-dangerous ops gated by default. `rig down` in particular is gated
via the prefix superset `Bash(rig down:*)` — harness rules at Claude
2.1.220 are prefix-only (flag-only patterns provably fail to gate target-
first forms such as `rig down <rig> --force`, which were slipping through),
so the prefix gate is the only shape that actually holds. Plain `rig down`
is gated in 0.4.8; selective allowance (e.g. `rig down <rig>` for a
specific target) is deferred to 0.5.0 server-side enforcement.
### `rig up` un-gated
The prior release's ask-gate on `rig up` is superseded — `rig up` is a
reversible op and does not warrant an interactive gate.
### Permission-policy foundation (framework for the built-in templates + skill that ship in 0.5.0)
- **Harness-neutral policy schema** — the permission-policy spec ships as
a harness-neutral surface with `default_posture`, `floor`,
`allow` / `ask` / `deny` expressed as **semantic actions**
(`push_to_remote`, `force_push`, `delete_files`, `read_secrets`,
`create_pr`, `publish_package`, `mutate_topology`, ...),
`destructive_class`, and a `source: builtin|custom` marker.
- **`rig setup --policy <name>`** — new flag on `rig setup` records a
deliberate permission-policy choice into an existing rig spec. Takes a
built-in name or a path to a custom spec. The **built-in policy files
themselves land in v0.5.0**; 0.4.8 ships the framework that consumes
them.
- **Two surfaces (documented, unchanged)** — the **LAUNCH-FLAG** surface
(Claude `--permission-mode`, Codex sandbox/bypass flags, Pi
`--approve` / `--no-approve`) is **stable and OpenRig-set
deterministically** — this is where the FLOOR and YOLO live. The
**CONFIG-FILE** surface (Claude `~/.claude/settings.json`, Codex
`config.toml`) is **chaotic across harness versions** and translated
interactively per harness version by an agent-driven skill —
`applying-a-permission-policy`, which lands as a bundled skill in
v0.5.0.
## Deployment Invariant (Operators Read This)
For the posture writes to reach seats, **the daemon's `HOME` must equal the
seat's tmux `HOME`**. This is a 2.1.220 settings-path class invariant that
operators need to know for the remote-host leg of any upgrade. Notes for
your host-upgrade checklist:
- On a local-only host, this is typically satisfied automatically.
- On a remote-host upgrade, verify HOME parity between the daemon process
and the tmux seat process before treating the upgrade as complete.
## Superseded / Withdrawn
An initial 0.4.8 attempt (with `dontAsk` baked as a **platform default**)
was withdrawn pre-cut on final review; the shipped 0.4.8 is a re-scoped
permission-agnostic base + policy-spec system. Nothing from the withdrawn
attempt shipped.
## Behavior + Compatibility
- **Migrations** — additive only. Existing v0.4.7 databases upgrade by
running `rig daemon start` on the new daemon.
- **Default launch posture** — changed from hardcoded `acceptEdits` to
configurable, default `dontAsk`. If a seat needs the prior behavior,
select `acceptEdits` explicitly.
- **Deny-set write location** — user-level `~/.claude/settings.json`, so
the deny set wins over project-local approvals. Writes are additive.
- **`rig up`** — no longer ask-gated; reversible ops don't warrant an
interactive gate.
## See Also
- `CHANGELOG.md` — the `[0.4.8]` entry.
- `docs/releases/v0.4.7.md` — the prior release (recovery honesty + starter bootstrap + skills wave + Slack + UI maintenance-mode).
- GitHub Release: https://github.com/mvschwarz/openrig/releases/tag/v0.4.8
+177
View File
@@ -0,0 +1,177 @@
# OpenRig v0.5.0
> **UI posture (unchanged from v0.4.7):** The web UI remains in
> **maintenance mode** — still ships, still runs, no new feature work.
> **CLI/TUI is the primary surface.** v0.5.0 lands the TUI (`rig` /
> `rig tui`) as the new mission-control home.
## Summary — Mission control in the terminal + context library + permission guarantee test-pinned + provider usage observability + plan amendment done right + honest CLI + build discipline
**Mission control in the terminal.** Typing `rig` (or `rig tui`) opens the
TUI: file-tree navigator, dense agent detail (cwd, runtime as text,
context %), topology graph with the whole fleet on one screen, honest
status/activity language, motion design, working scrolling, and honest
width-clip/scope indicators throughout.
**0.5.0 contains 0.4.8 in full.** One lineage, no divergence, no dual
maintenance: 0.5.0 = 0.4.8 (the permission-policy release) + the slices
below. The 0.4.8 code + shipped skills all reside on the 0.5.0 lineage
via the back-merge that reconciles the 0.4.8 release-artifact history with
the 0.5.0 working lineage.
Migrations are additive only. Existing v0.4.8 databases upgrade by running
`rig daemon start` on the new daemon.
## What Shipped
### Permission guarantee, now test-pinned
0.5.0 upholds the 0.4.8 promise — **OpenRig never writes permission entries
into your Claude `settings.json`** — and pins it with a permanent guard
test plus an empty-writer sweep. The one sanctioned exception is the
project-local `acceptEdits` floor that 0.4.8 itself defines. Warning
ordering in `permission-policy-discovery` emits pre-existing main-floor
warnings first, then the permission-policy attachment warning;
presentation-only, semantic fence unchanged.
### Context library
`rig context` stores and composes context; `rig walk` delivers it paced;
`--context` / `--body-context` ride `send` / `broadcast` / `queue-create`
with snapshot + provenance. Grammar is strict: **nouns store and compose**
(`rig context` never delivers); **verbs deliver** (`rig send`, `rig
broadcast`, `rig walk`, or `rig queue` via `--context` / `--body-context`).
The 0.4.x context-window usage viewer is removed; the `rig context` name
belongs to the library.
### Behavior change (0.4.8 → 0.5.0)
`rig.yaml` startup `context_pack` entries are no longer delivered at
instantiation. **They are rejected with a teaching error pointing at
compose + delivery verbs.** Users who adopted them on 0.4.8 (shipped days
ago; tiny exposure) should compose the pack via `rig context compose` and
deliver via a dedicated delivery verb (`rig send --context`, `rig
broadcast --context`, `rig walk`, or `--context` / `--body-context` on
queue create). The bundle router populates the library store without
delivering (delivery-free-noun ruling applied at the startup surface).
### Provider usage observability
The daemon tracks account-level usage per host — the "am I about to hit a
usage limit" question — exposed via `GET /api/provider/usage` and `rig
provider status`. Honest explicit-unknown and conflict-shows-both-facts;
Codex account-switch flows preserved.
### Plan amendment done right
`rig scope slice approve --re-approve --reason` re-stamps a locked plan
with an append-only audit trail, killing the old `already_approved`
Status-note workaround.
### Honest CLI output
`rig ps` says when it is showing one rig of many; `rig send --json`
returns structured errors as `{fact, consequence, action}`; the activity-
hook fix ends the fleet-wide "producer link stale" advisories (operator-
facing quality improvement worth naming).
### Build discipline
Contributor gates/lanes SSOT lives at `docs/reference/developing.md`
(encoded by the slice-12 gates policy).
### UI status (unchanged from v0.4.7)
The web UI is formally in **maintenance mode** as introduced in v0.4.7 —
still ships, still runs, no new feature work. CLI/TUI is the primary
surface. v0.5.0's TUI (`rig` / `rig tui`) is where mission-control
investment lands going forward. Never "deprecated" — the UI is not
removed and existing deployments continue to work.
### Permission policies — built-in templates + custom + agent-driven translation
Building on the v0.4.8 policy-spec system, v0.5.0 ships **the built-in
policy templates + the agent-driven skill that translates them into the
target harness's live config**.
- **Five built-in policy templates** — `locked`, `standard`, `open`,
`yolo`, `none`. Read-only from the package; copy to customize.
- **`rig setup --policy <name>`** — records the chosen policy into a rig
spec. Takes a built-in name (`locked | standard | open | yolo | none`)
or a path to a custom policy file. Custom policies carry
`source: custom` in the spec.
- **`applying-a-permission-policy` — agent-driven, version-stamped
translator (bundled skill).** At rig setup / preflight, the skill reads
the policy spec, grounds itself in the seat's current harness version
(Claude 2.1.220 / Codex 0.120.0 / Pi 0.83.0 at ship time), shows the
concrete diff before writing, and lands the config into Claude
`~/.claude/settings.json` and/or Codex `config.toml`. Never blind
writes. The `applying-a-permission-policy` skill is agent-driven on
purpose — harness permission formats are a moving target, and a
deterministic writer would foot-gun on the next harness release.
- **Two surfaces (unchanged from v0.4.8, called out honestly)** —
**LAUNCH-FLAG** (stable, OpenRig-set deterministically): the **FLOOR**
(Claude `acceptEdits`, Codex workspace-write) and **YOLO** (Claude
`--dangerously-skip-permissions`, Codex full-bypass). **CONFIG-FILE**
(chaotic, translated per harness version by the skill): the
allow/ask/deny rules for `~/.claude/settings.json` +
`config.toml`.
- **Deterministic parts vs best-effort parts** — the LAUNCH-FLAG floor +
YOLO are deterministic. Fine-grained CONFIG-FILE rule translation is
**best-effort** — the skill surfaces prefix-collision (e.g.
`push_to_remote` vs `force_push` both matching `Bash(git push:*)`),
target-first leaks (e.g. `rm <t> -rf` slipping past
`Bash(rm -rf:*)`), and Claude-only network-egress non-enforceability
to the operator honestly via the diff-before-write flow. If a
translation is uncertain, fall back to a blunt instrument (YOLO or
floor) or hand-edit — those remain valid paths.
### Bundled skills
Two new bundled skills join the shipped set alongside the 0.4.8 skills:
- `applying-a-permission-policy` — Tier-A agent-driven translation for
permission policies (see the Permission policies section above).
- `delegating-work` — Tier-A every-agent distribution.
The `openrig-user` `SKILL.md` is updated with the 0.5.0 context-library +
paced-delivery + `--context` / `--body-context` awareness. Two additional
0.5.2-lane maturation-gated skills (`retiring-and-inheriting-a-seat` and
`oversight-team`) sit in the oracle at draft stage and are correctly
deferred to a later release per the maturation-gate contract.
## Known Issues
- **GAP-7 Codex-`HOME` product fix** (seal CLEAR `b7f4cb7d`) — accepted
with fold-rides-release-sequencing but fell off the fold-wave
enumeration and is **NOT in released 0.5.0 by content**. Ships in
0.5.1 as a ready-accepted early bugfix atom. Class: sibling of the
slice-03 omission, caught by census not damage. If you rely on Codex
seats picking up the daemon's `HOME` setting for the permission-
posture writes, this is the fix that is still pending; the deployment
invariant from v0.4.8 (daemon `HOME` == seat tmux `HOME`) remains the
operator-side workaround until 0.5.1 lands.
## Upgrade Notes
- Migrations additive-only; run `rig daemon start` on the new daemon.
- Any rig `rig.yaml` still declaring a startup `context_pack` will see the
teaching-error rejection above; migrate to the compose + delivery-verb
pattern.
## Behavior + Compatibility
- **Migrations** — additive only.
- **`rig.yaml` startup `context_pack`** — rejected at instantiation with a
teaching error. Migrate to `rig context compose` + delivery verbs.
- **Context viewer removal** — the 0.4.x context-window usage viewer is
removed; the `rig context` name is the library.
- **Permission-writer surface** — pinned by a permanent guard test:
OpenRig writes zero permission entries into `~/.claude/settings.json`
beyond the sanctioned project-local `acceptEdits` floor.
## See Also
- `CHANGELOG.md` — the `[0.5.0]` entry.
- `docs/releases/v0.4.8.md` — the prior release (permission-posture fast-follow).
- GitHub Release: https://github.com/mvschwarz/openrig/releases/tag/v0.5.0