返回 DeepSeek-Reasonix
CHANGELOG.md
根目录 / CHANGELOG.md
1 # Changelog
2
3 All notable changes to the Go line (Reasonix 1.0+) are recorded here. The legacy
4 `0.x` TypeScript history lives on the [`v1`](https://github.com/esengine/DeepSeek-Reasonix/tree/v1)
5 branch.
6
7 ## Unreleased
8
9 ### Desktop conversation creation
10
11 - Local **New Conversation** creates a distinct formal session immediately,
12 including when another empty conversation already exists. First send uses
13 that identity. Closing or archiving the last conversation leaves the welcome
14 page; it does not create a replacement.
15 - Unsent local inputs are saved independently of chat history. Previous project
16 drafts remain available through **Previous drafts**. Unconfirmed submissions
17 are retained for inspection and are never automatically replayed.
18 - Automatic historical empty-session cleanup is retired. Existing trash and
19 manual restore remain available. Session v5 and workspace registry v3 remain
20 unchanged. Downgrading to 1.38.9 is unsupported; 1.38.10 also cannot read
21 revision-3 sessions introduced by #10545. Returning from 1.38.11 preserves
22 new input files and requires review when session history has advanced. See
23 [compatibility and recovery](docs/manual-session-rollback.md).
24
25 ### Added
26
27 - **Editable message queue (Desktop):** full-text editing in the original queue row,
28 pointer and keyboard reordering, move-to-top/bottom actions, and a pause
29 control. Saves preserve message identity, order and attachments; conflicting
30 or unconfirmed saves retain the user's draft. Remote editing requires the
31 additive `inbox-mutations-v1` capability. Editing temporarily hides the main
32 composer; saving or cancelling restores its draft, attachments and focus.
33 Switching sessions protects newer edits from delayed replies; loading the
34 latest version can recover after the active session selection changes.
35
36 - **Live file observations:** structured file tools now protect mutations with
37 a host-owned current-version observation. Any successful text window is
38 sufficient, successful writes refresh the version, and external changes
39 produce `FS_STALE_VERSION` without blocking unrelated tools.
40
41 - **MCP 2026-07-28 protocol:** multi-round-trip form/URL elicitation across
42 Desktop, CLI TUI, and serve; headless entries stay on the core surface and
43 cancel unanswered requests instead of guessing.
44 - **MCP Apps 2026-01-26 (Desktop):** inline app surfaces in tool cards behind
45 a per-server double-iframe sandbox, app-tool visibility metadata, bounded
46 aggregate local presentations, tab-bound AppBridge routing and teardown,
47 immutable digest-bound resource snapshots, and confirmed external links;
48 local rich results, instance-gated app tool calls, and the four-layer
49 capability matrix in MCP status.
50 - **Profile-scoped MCP schema caches:** capability-declaring hosts keep their
51 own `v3` cache files so catalogs negotiated under different client
52 capabilities never cross-read.
53
54 ### Changed
55
56 - Sending while a task is running now queues a follow-up by default. Use
57 **Guide current turn** for explicit mid-turn guidance. Stopping the current
58 task retains pending messages; the queue has separate pause/delete controls.
59
60 - **Persistent bash PTY:** ordinary foreground `bash` calls in a session now
61 share one PTY, so `cd`, exported variables, and shell functions survive
62 across calls. Output stays byte-identical to one-shot execution, stdin stays
63 detached, and a timeout or cancel reports partial output and says the shell
64 was reset. Background jobs, commands that background a child, per-call
65 write-root escalations, host terminals, and PowerShell hosts stay one-shot.
66 The bash tool schema and description are unchanged.
67
68 - **CLI YOLO shortcuts:** the CLI displays the unrestricted preset as YOLO;
69 `Ctrl+Y` toggles the canonical `danger-full-access` permission, while
70 `Shift+Tab` cycles Read only → Workspace write → YOLO → Plan.
71
72 - **Harness-style scheduling and recovery:** calls take effect in execution
73 order, including same-batch read/edit sequences. Bounded reads create no
74 completion debt. Unknown external effects are durable advisory facts and no
75 longer block tools or trigger replay. Proof/settlement tools, Auto Guard,
76 recovery actions, and repeat-call rejection are retired; identical calls get
77 non-blocking reminders at counts 3, 5, and 8.
78
79 - **Fact-driven execution:** Ordinary requests always enter the executor.
80 There is no automatic simple / light / full task mode and no per-turn
81 `TaskPolicy` classification. The planner runs only for an explicit Plan,
82 an approval boundary, or Goal start. The host builds verification
83 obligations from concrete tool effects and receipts. Plan, Goal,
84 permission, and sandbox stay independent. Tool schemas and the executor
85 system prefix stay byte-stable. Historical `<execution-policy>` tags remain
86 readable on old sessions and are stripped from new provider context.
87 Old `--preset`/`--profile` compatibility no-ops are unchanged.
88
89 - **Remote connect wizard host picker:** Step 1's host field now opens the
90 saved SSH connections through an explicit chevron dropdown on the input's
91 right edge instead of the old focus-triggered popup. The dropdown lists
92 every saved connection unfiltered, appends non-standard ports to each row,
93 leads with a "saved SSH connections" caption, and closes on pick, arrow
94 toggle, Escape (before the Escape that exits the wizard), or an outside
95 pointer press. The arrow is hidden while no hosts are saved and disabled
96 while a connection is busy.
97
98 ### Fixed
99
100 - **Setup menus in narrow terminals:** `reasonix setup` and the other
101 arrow-key menus clip every row to the terminal width. A row that soft-wrapped
102 used to throw off the redraw, stacking a fresh copy of the header and the
103 wrapped rows on screen with each keypress.
104
105 - **Read evidence recovery:** partial reads no longer freeze independent work
106 or ordinary final answers. Explicit full reads retain bounded completion
107 checks. Rejected edits track operation/version requirements so successful
108 retries, fresh versions and confirmed deletion retire obsolete blocks.
109 - **File and shell boundaries:** guard raced creates/overwrites and move-source
110 changes, recognize `git --no-pager` inspections, and retain structured recovery
111 diagnostics without changing provider tool schemas.
112
113 - **Relay image input:** ID-only or invalid model metadata now stays unknown.
114 Both Desktop model editors expose per-model Auto / On / Off overrides, with
115 official protocol limits retained. A separate V2 discovery cache rejects stale
116 results; saved settings and runtime image serialization share one resolver and
117 apply at Controller rebuild boundaries. Legacy configuration remains readable.
118 - **中转站图片输入:** 缺失或无效的模型能力显示“图片能力未识别”,两个编辑入口
119 均可逐模型选择“自动 / 开启 / 关闭”。独立 V2 缓存隔离旧错误声明并防止陈旧结果
120 覆盖;保存设置与实际图片请求统一解析,在 Controller 重建边界生效,兼容旧配置。
121
122 - **Deterministic natural-turn completion:** removed the extra completion
123 validator model request. Clean model stops now finish from provider/tool state;
124 true zero-content responses retry the frozen request at the Agent step
125 boundary, while explicit host-owned readiness and safety gates remain active.
126 Legacy completion-validator configuration and `completion_uncertain` event
127 values remain readable for compatibility but are no longer produced by the
128 validator path.
129
130 - **serve Host-header allowlist:** `reasonix serve` now rejects requests whose
131 `Host` is neither loopback nor the actual listen address (HTTP 421), closing
132 the DNS-rebinding bypass of the JSON content-type CSRF guard — a rebind page
133 becomes same-origin with the loopback listener and could previously drive
134 `/bypass`, `/submit`, and read `/history`. `behind_proxy` deployments and
135 wildcard/non-loopback binds are exempt. The non-loopback plaintext-HTTP
136 startup warning now also fires — loudest — for the unauthenticated `auth =
137 none` case that used to stay silent.
138
139 - **Preview read confinement:** `write_file` / `edit_file` / `multi_edit`
140 previews now apply the same `confinePreview` boundary as `delete_range` /
141 `delete_symbol`. A model-supplied absolute path outside the workspace roots
142 previously read the file (rendering its contents into the approval card and
143 session log) even though Execute would refuse the write.
144
145 - **Clean-filter hardening on internal diffs:** gitcmd diff invocations now
146 neutralize every `filter.<driver>` defined in the repository's local
147 `.git/config` (`clean=` emptied, `required` forced off), so viewing a changed
148 file's diff can no longer execute a repository-configured clean filter via
149 `.gitattributes`. Emptied filters are identity pass-throughs: the diff still
150 renders the real working-tree change.
151
152 - **install_source proxy SSRF parity:** the install_source SSRF dial guard now
153 also validates the request destination (IP literals) at the RoundTripper
154 boundary, so a configured HTTP/HTTPS proxy can no longer forward a blocked
155 target (cloud metadata, RFC1918, link-local, CGNAT) that the dial-time check
156 never sees — matching web_fetch's proxy-path behavior.
157
158 - **awk approval classification:** the bash indirect-execution classifier now
159 treats `awk`/`gawk`/`mawk`/`nawk` with an inline program (anything not read
160 via `-f`/`--file`) like `python -c`: it always requires human approval and
161 can never be covered by a remembered reusable prefix rule. `awk
162 'BEGIN{system("…")}'` previously fell through to the reusable class.
163
164 - **cargo check/doc read-only correction:** the legacy read-only command table
165 no longer lists `cargo check` / `cargo doc` as permission readers — cargo
166 executes the crate's `build.rs` for both. The effect classifier already
167 billed them as code-executing writers; the stale table entry (and its test)
168 now agree. Only `cargo search` remains read-only.
169
170 - **Compact MCP discovery:** `use_capability(action=list)` now returns one
171 compact summary per configured MCP server instead of expanding every cached
172 tool description, including tools from disabled servers. Inspecting one
173 enabled `mcp-server:<name>` still returns its live or cached directory
174 without starting it, while direct known-ID calls, routing, authorization,
175 and the fixed provider-visible tool schema remain unchanged.
176
177 - **Project MCP session reliability:** The MCP client now uses the official Go
178 SDK for stdio, legacy SSE, and Streamable HTTP while retaining Reasonix's
179 existing configuration, OAuth, process isolation, and schema-cache contracts.
180 Streamable HTTP opens its long-lived GET/SSE listener immediately after
181 initialization, so JetBrains project-level `.mcp.json` servers no longer lose
182 their pending session before the first tool call. Lost sessions converge on
183 one bounded rebuild and one replay, read-only surfaces consume every cursor
184 page, prompts/resources share the tool session, and shutdown terminates HTTP
185 sessions and local processes. MCP calls also accept a single JSON-object
186 string in `use_capability.arguments`, while rejecting arrays, scalars, invalid
187 JSON, and nested encoded strings. `/mcp` and Desktop expose redacted protocol,
188 listening, reconnect, and error-category diagnostics without session IDs.
189
190 - **v1.24.2 session snapshot & recovery root fix:** Keep PR #7982's WAL/CAS/lease
191 safety foundation, but replace process-level "I hold a lease" ownership with a
192 generation-bound `SessionWriteAuthority`. Same-revision tool-preview/load
193 reshapes no longer false-diverge; recovery files are bounded to one path per
194 writer/lineage; empty checkpoints heal from their own WAL; projection lineage
195 rebinds across upgrade/model switch and inherits across recovery forks without
196 changing provider-visible prompt bytes. Catalog upgrades to disposable
197 `session-catalog/v3.sqlite` with recovery lineage roles
198 (`normal|covered_copy|adopted|diverged`); covered idle copies move to the
199 recoverable `.trash` using a 15-minute idle threshold applied on two early
200 sweeps (at startup and ~20 minutes later), then a 24-hour threshold on the
201 6-hour background ticker; independent diverged branches stay and are listed
202 for user choice. v1/v2 catalogs are
203 left byte-unchanged for coexistence/downgrade.
204 **v1.24.1** only hid/reclaimed already-created covered copies and fixed Windows
205 flash-window startup; **v1.24.2** stops the misclassification source and repairs
206 existing user directories without rewriting authoritative JSONL/WAL/sidecar data.
207
208 - Goal now runs continuously by default: the former 16-round per-Run boundary,
209 10/20/40 cross-Run quotas, default wall-clock budget, and numeric
210 no-progress/Todo-stall pauses no longer stop valid work. Progress guards still
211 detect repeated host outcomes and zero-evidence work, but redirect the model
212 to re-plan instead of producing `goal_run_budget` or `goal_stuck`. Explicit
213 `[agent].goal_token_budget`, `--max-steps`, positive time/cost budgets, manual
214 pause/stop, genuine user/external blockers, and evaluator fail-closed behavior
215 remain available. The Goal token budget defaults to `0` (off); resuming its
216 `budget_spend` pause grants a fresh slice without clearing cumulative usage.
217 Goal status reports turns, provider requests, tokens, the optional configured
218 token threshold, and cumulative active work time. Bot `max_steps` also
219 defaults to `0` (continuous), while positive user configuration is enforced.
220
221 - Removed numeric Goal pauses in existing sidecars automatically normalize to
222 `running` without sending a model request. Active Goal sidecars write
223 `turnsLimit: -1` as a downgrade-safe unlimited sentinel while public runtime
224 APIs retain deprecated limit fields as `0`. The migration preserves unknown
225 fields, todos, checkpoints, usage, evidence, and historical metadata.
226
227 - Goal is now the sole long-task runtime. Historical AutoResearch sidecars
228 migrate transactionally into Goals with research compatibility metadata. Invalid archives block
229 fail closed and remain read-only, retaining the task id and compatibility mode
230 for a restart or `/goal resume` retry; successful Goal-only sidecars omit the
231 old task id and write an explicit downgrade fence so previous readers cannot
232 reactivate the removed runtime.
233
234 - Context-dependent workflow tools now share one host-side execution boundary.
235 Goal, Plan sign-off, and background-job calls cannot reach permissions,
236 hooks, leases, or Execute outside their owning context; mixed batches execute
237 valid calls once and stop safely after one repair. Child agents also isolate
238 inherited Goal, Jobs, and live memory queues, while persisted tool identity
239 records the effective child schema projection.
240
241 - **Issue #7575:** Linux Bash under bubblewrap no longer mounts a fresh empty
242 `--tmpfs /tmp` on every call. Consecutive commands in the same logical session
243 now share a private temporary directory (bound at `/tmp` on Linux, exported via
244 `TMPDIR`/`TMP`/`TEMP` on all platforms) without exposing the host public
245 temporary root. `/new`, `/clear`, resume of another session, and branch
246 switches rotate the directory; model/settings hot rebuilds keep it. Sub-agent
247 runs get independent directories. Temporary files are not durable across process
248 restarts.
249
250 ### Added
251
252 - Added `[ui].show_turn_usage` so CLI/TUI users can hide per-request token and
253 cost receipts from transcript scrollback without disabling usage accounting.
254
255 ## [1.20.0] — 2026-08-05
256
257 Extension kernel, Task Monitor, and safer Goal completion.
258
259 Compact decision surfaces, local decision receipts, unified extension kernel,
260 native Task Monitor, bounded sub-agent progress, Goal fail-closed completion,
261 MiMo and DashScope Responses fixes, SSH remote access simplification, and
262 multiple Desktop stability improvements.
263
264 ### Highlights
265
266 - **Unified Extension Kernel and Extension Protocol v1**: Immutable runtime
267 snapshots, fail-atomic reload, Plugin Manifest v1 (prompts, themes, full-trust
268 code runtimes), stable JSON-RPC sidecar protocol, interceptor dispatch,
269 streaming provider adapter, structured UI, and Go SDK.
270 - **Native Task Monitor**: Monitor agent tasks natively in CLI and Desktop with
271 lifecycle semantics and session-scoped summary view.
272 - **Bounded Sub-agent Progress Forwarding**: Forward structured progress for
273 `task`, `parallel_tasks`, and `fleet` without flooding the parent stream.
274 Renders nested lifecycle cards in Desktop and stable per-child transcript
275 slots in CLI.
276 - **Goal Completion Fail-Closed**: Replace free-form Goal footer markers with a
277 stable `update_goal` tool and epoch-scoped per-turn reports. Centralized
278 completion logic with bounded evaluator, progress-aware budgets, and
279 pause/resume controls.
280 - **Ablation Subsystem Switches**: Switch subsystems off behind one shared
281 vocabulary for controlled experiments. Includes planner, subagent, retrieval,
282 evidence, and compaction.
283 - **Benchmark Cost per Solved Task**: Report cost per solved task, tokens per
284 solved, median wall time, and failure-class breakdown in e2e reports.
285 - **Compact Decision Surfaces and Local Receipts**: Compact footer decision-card
286 layout with bounded scroll, dense action rows, and overflow disclosure.
287 Record bounded Ask, approval, and recovery decisions as local transcript
288 receipts.
289 - **Simplified SSH Remote Access**: Remove Remote Workbench protocol and
290 stacks; reuse CLI/Serve remote model. Desktop opens per-host native web child
291 windows via SSH. Keyless remote Serve setup with loopback-only page.
292 - **Model Usage Charts with Primer Palette**: Replace monochrome accent ramp
293 with GitHub Primer data-viz two-set categorical palette. Fix donut overflow
294 on hover and keyboard accessibility.
295 - **Cross-platform Extension and Task Monitor Reliability**: Make
296 content-reference eviction deterministic, reject Unix and Windows absolute
297 plugin paths consistently, stabilize parallel-task cancellation, and restore
298 reliable Windows validation for Task Monitor and remote provider setup.
299 - **MiMo and DashScope Responses Wire Alignment**: Fix multi-turn tool loops,
300 reasoning round-trip, JSON output for MiMo; fix DashScope second-turn 400
301 error, all-zero usage suppression, and vendor-aware cache TTL.
302 - **Desktop Stability Fixes**: Recover stuck updates and legacy WebKit, contain
303 macOS alias repair startup crashes, keep composer overflow stacks readable,
304 and harden account verification and community flows.
305 - **Remote Web Recovery After SSH Drops**: Add integration regression test for
306 SSH drop, forward recovery, and window reload. Document transient outage
307 behavior.
308 - **CI: Auto-minimize Activity-Farming Spam Comments**: Detect and minimize
309 template spam comments from non-contributor accounts based on structural
310 signals.
311
312 ### Added
313
314 - Added Extension Protocol v1 and the unified extension kernel: installed or
315 linked sidecars can contribute tools, skills, commands, hooks, MCP servers,
316 providers, interceptors, and structured UI surfaces through a versioned
317 NDJSON contract and the public Go SDK. CLI, Desktop, ACP, and Serve support
318 fail-atomic runtime reloads; Serve also renders extension surfaces and lists
319 extension-hosted providers without exposing credentials.
320 - Added the structured Goal completion protocol: the always-registered
321 `update_goal` tool (continue/complete/blocked with reason and next_action)
322 replaces the `[goal:*]` footer markers. The Goal FSM is now the exclusive
323 cross-turn decision point and validates every complete claim against Delivery
324 readiness; when the model submits no report, an independent bounded evaluator
325 (recovery_model → guardian_model → main model, no tools/history, usage
326 attributed to `goal-evaluator`) judges the turn once, and any evaluator
327 failure pauses the goal instead of continuing silently.
328 - Added Goal budget classes with safe pauses: simple 10 turns / 200k tokens,
329 write 20 turns / 400k tokens, AutoResearch 40 turns / 800k tokens, and a
330 4-turn no-host-verifiable-progress gate. Pauses keep all Goal state; `/goal
331 resume` continues and adds one slice of the current class when the pause was
332 budget-related. `/goal status` shows the full turn/token/no-progress runtime,
333 and `/goal pause` manually suspends a running Goal.
334 - Added the `goalRuntime` nested view to the desktop Meta, the remote protocol
335 (`session/goal/pause` operation, `goalRuntime` DTO on session meta), and the
336 ACP status payload; the desktop Composer goal menu shows the runtime summary
337 with distinct pause/end/resume actions.
338
339 ### Changed
340
341 - Delivery no longer retries final-answer readiness with hidden model messages:
342 a plain Delivery run ends on the first unsatisfied final answer and surfaces
343 the recovery card, while a Goal + Delivery run has the Goal FSM absorb the
344 failure and continue under budget with the missing requirements as the next
345 turn's prompt. Historical `[goal:*]` footers are stripped from old transcripts
346 for display only and never participate in state decisions.
347 - Added a **Remote SSH** module (VS Code Remote-SSH style): a user-global
348 `[remote]` host config, `reasonix remote` CLI (add/list/remove/import/test/
349 connect/status/forward/serve/fs) and `/remote` slash command, an SSH transport
350 with trust-on-first-use host-key verification, keepalive + exponential-backoff
351 reconnect, `-L`/`-R` port forwarding, and SFTP file access. `connect`
352 bootstraps a persistent `reasonix serve` on the remote host and tunnels its
353 loopback port so the full agent runs remotely. The desktop app adds a
354 **Settings -> Remote SSH** host manager, a remote file browser/editor, a
355 port-forwarding panel, and a status-bar connection chip. Linux/macOS remotes.
356 - Added `reasonix serve --port-file/--token-file/--pid-file` so a supervised
357 headless serve can bind an ephemeral port and read its auth token from a file
358 (keeping it out of `ps`).
359 - Added an authenticated, loopback-only Provider setup page for `reasonix
360 serve`. A Serve whose selected Provider is missing its API key now remains
361 reachable, stores the submitted key in that host's Reasonix credential file,
362 and rebuilds the active controller in place without restarting Serve.
363 - Added Claude Code-style searchable CLI pickers for models, providers, and
364 sessions, with arrow, Vim, and `Ctrl+P` / `Ctrl+N` navigation.
365 - Added `-p` / `--print`, `text`, `json`, and `stream-json` output modes for
366 one-shot use and automation.
367 - Added session-scoped `--allowed-tools`, repeatable `--add-dir`, Claude-compatible
368 permission modes, flexible `--resume [QUERY]`, and the `--copy` resume escape
369 hatch.
370 - Added `/status` details for the active model, effort, cache, Git state,
371 background jobs, work profile, and provider balance where available.
372 - Remote SSH workspaces now open as a standalone remote web window again.
373 Opening a workspace from the status bar or the Remote Server tab starts or
374 reuses the remote `reasonix serve`, tunnels its loopback port, and opens the
375 Serve web client in a dedicated per-host window. The remote web page uses
376 the provider configuration and API keys on the **remote** host; the desktop
377 no longer exposes its local providers to remote hosts. If the selected remote
378 Provider is missing its API key, the window opens a setup page that saves the
379 key only on that host and then opens the normal Serve UI. The Remote Workbench
380 protocol, its Provider Broker, and the same-window remote projection were
381 removed. Legacy mirror and provider-trust files are not deleted
382 automatically; Settings -> Remote SSH shows a cleanup card when they exist.
383 The hidden `remote attach-workspace`, `remote runtime-workbench`, and
384 `remote workbench-build-id` commands now fail with a pointer to
385 `reasonix remote connect <host> --open`.
386 - Automatic Plan Mode has been retired. Plan Mode is now always entered through
387 an explicit user choice, and the one-time config v5 upgrade removes legacy
388 `agent.auto_plan` and `agent.auto_plan_classifier` values so upgraded users
389 receive the same behavior as new users.
390 - `Shift+Tab` now cycles CLI safe modes from Ask to Auto to Plan, while YOLO
391 remains an independent `Ctrl+Y` toggle.
392 - Model, provider, resume, and approval menus now use consistent row selection;
393 slash completion, help, aliases, and dispatch share one command registry.
394 - The full-screen CLI composer now uses theme-accented borders and a slim bar
395 cursor by default, grows within the available terminal height, scrolls long
396 drafts independently, and preserves selections across explicit image paste.
397 - The persistent CLI footer now uses a responsive, theme-aware layout for
398 interaction state, model, effort, localized work mode, Git identity, cache,
399 context, compaction headroom, jobs, and balance. Narrow terminals move or
400 compact complete groups instead of clipping labels.
401 - CLI clipboard actions now separate terminal-native text paste from explicit
402 image paste: `Ctrl+V` on macOS/Linux, `Alt+V` on Windows, or `/paste-image`.
403 Local transcript copy verifies the native clipboard write, while SSH uses a
404 clearly labelled OSC 52 fallback.
405 - Runtime rebuilds after model, effort, or work-mode changes now preserve the
406 conversation, session permission overrides, additional directories, and
407 session lease ownership.
408 - Agent execution now monitors host-observed Todo progress automatically. A
409 stalled current item receives a recovery nudge after 8 tool-call rounds with
410 no new completion, unique read, command, or mutation, and pauses with saved
411 work after 16. Exact repeats do not renew the progress lease; real work does.
412 Two-level task lists keep the single in_progress contract: the active
413 sub-step is the only current item while its phase stays pending, and the
414 phase becomes in_progress to sign off only after all of its sub-steps are
415 completed. A level-1 sub-step with no phase header above it is rejected.
416 Executor and planner rounds now use automatic progress management. Retired
417 `[agent].max_steps` and `planner_max_steps` keys remain parseable for upgrades,
418 but are ignored and removed by a one-time migration so stale hidden limits
419 cannot truncate new behavior. One-off CLI and unattended bot limits remain.
420
421 ### Fixed
422
423 - Fixed long parallel sub-agent research being silently lost when combined
424 `parallel_tasks` or `fleet` answers exceeded the single-tool output limit.
425 Persisted sessions now keep each child transcript independently, return a
426 bounded fair preview plus stable reference for every result, and page full
427 answers through the conversation-scoped `read_subagent_result` tool.
428 - Fixed Remote Workbench failing with only `initialize: workbench-desktop:
429 connection closed` on fresh or cross-platform SSH hosts. Desktop now proves
430 the exact Host CLI Build ID, provisions the matching verified release without
431 requiring remote npm, runs the managed binary explicitly, and preserves a
432 safe structured bootstrap error when the remote command exits early.
433 - Hardened Bash permission reuse for dynamic and indirect execution. Parameter/arithmetic expansions,
434 assignments, redirects, heredocs, and globs can only be remembered as exact
435 `Bash=<literal>` rules, while still using Auto's normal fallback. Nested or
436 indirect execution now requires a human in interactive Ask/Auto and fails
437 closed in headless Ask/Auto/DontAsk. Broad Bash rules, Guardian/hook allows,
438 and the approved-plan window can no longer silently authorize that stricter
439 class; YOLO remains the explicit full-access bypass and sandbox enforcement
440 is unchanged.
441 - Fixed Desktop sessions incorrectly locking themselves during Goal + Delivery
442 mode changes, controller rebuilds, duplicate-tab restore, and background
443 reattachment. Desktop now keeps one process-local runtime owner per canonical
444 session, fences stale controller events by runtime epoch, blocks sends until
445 that runtime is ready, and scopes single-instance ownership to
446 `REASONIX_HOME` instead of the executable path. Switching saved sessions is
447 now transactional: a target build, restore, or lease failure leaves the
448 current controller, lease, path, mode profile, and runtime epoch untouched.
449 - Stabilized the desktop rich composer caret after skill and plugin invocation
450 tags. DOM→model and model→DOM selection mapping now treat invocation chips as
451 zero-length atoms while still counting user text that lands inside the NBSP
452 caret anchor (common on Windows WebView2), restore both selection ends, and
453 recover the insertion point from a `beforeinput` snapshot when the browser
454 temporarily loses selection — so mid-text edits no longer jump to the end.
455 - Isolated the Windows desktop WebView2 shell from stale system proxies, so an
456 exited proxy client cannot leave the embedded UI hidden during startup. If
457 WebView2 still does not reach DOM-ready within 15 seconds, Reasonix now shows
458 the native window with a recovery prompt instead of appearing not to launch.
459 Remote Markdown images are fetched by the backend with Reasonix's proxy
460 configuration instead of bypassing that proxy through the isolated WebView.
461 - Restored captured-mouse right-click text paste, made composer drag selection
462 copy through the verified native clipboard path, and kept non-Git footer
463 telemetry left-aligned without reserving an empty data band.
464 - Restored stateful MCP behavior after the v1.17.13 regression: user-added
465 servers work without extra trust settings (including delivery-mode on-demand
466 calls), repository-provided servers use one exact launch confirmation, and
467 stdio tools reuse one persistent process so browser sessions survive across
468 calls without repeated startup latency. The former trust/reverify/catalog
469 management UI and CLI are removed.
470 - Localized persistent-footer labels and displayed work-mode values in English,
471 Simplified Chinese, and Traditional Chinese, while keeping command arguments
472 stable.
473 - Restored the `0.53` content boundary: model output, tool output, session
474 transcripts, recovery branches, and background-job artifacts retain their
475 original text instead of being rewritten by heuristic secret redaction.
476 Credential masking remains in key-entry summaries and explicit diagnostic or
477 session-cleanup paths. Transcript-bearing session/job sidecars are kept
478 private (`0600`, with private job directories), and the retired
479 `redact_tool_output` setting is removed with a one-time upgrade notice.
480
481 ### Notes
482
483 - Full bilingual release notes:
484 <https://reasonix.io/changelog/v1.20.0/> ·
485 [GitHub release](https://github.com/esengine/DeepSeek-Reasonix/releases/tag/desktop-v1.20.0).
486 - The detailed entries below accumulated on `main-v2` after 1.0.0 and shipped
487 across 1.1.0–1.20.0; per-version attribution lives in the per-version release
488 notes linked above.
489
490 ## 1.1.0 – 1.19.7
491
492 Per-version entries for the intermediate releases are published in the
493 [bilingual release notes](https://reasonix.io/changelog/) and on the
494 [GitHub releases page](https://github.com/esengine/DeepSeek-Reasonix/releases).
495
496 ## [1.0.0] — 2026-06-03
497
498 First stable release — a **ground-up rewrite in Go**. Not an upgrade of the `0.x`
499 TypeScript line; a new codebase that becomes the default (`main-v2`).
500
501 ### Highlights
502
503 - **Go kernel**: a single static binary (CGO-free), cross-compiled for
504 darwin/linux/windows on amd64 + arm64. Distributed via npm (the package wraps
505 the native binary), Homebrew (`esengine/reasonix` tap), and release archives;
506 no Node runtime needed to run it.
507 - **Agent core**: the loop, built-in tools (read/write/edit/multi_edit/glob/grep/
508 ls/bash/web_fetch/todo_write), permission gate, sandboxed bash, and the
509 DeepSeek prefix-cache–oriented design.
510 - **Subagents**: `task` plus explore/research/review/security_review skill agents.
511 - **Skills & hooks**: Claude-Code-style skills (`internal/skill`) and hooks
512 (`internal/hook`), symlink-aware and slash-integrated.
513 - **MCP client**: connect external servers over stdio / Streamable HTTP; reads
514 `[[plugins]]` and a Claude-Code `.mcp.json`.
515 - **Code intelligence via CodeGraph**: a tree-sitter symbol/call graph
516 (`codegraph_*` tools) replaces embedding semantic search — no embedding service
517 or API cost. Fetched into a local cache on first use (or `reasonix codegraph
518 install`) and indexed in the background, so installs and startup stay fast.
519 - **Plan mode** with evidence-backed step sign-off (`complete_step`).
520 - **Memory**: `REASONIX.md` hierarchy + auto-memory, folded into the cache-stable
521 prefix.
522 - **ACP** (`reasonix acp`) and an HTTP/SSE server frontend; desktop app (Wails).
523
524 ### Fixed
525
526 - **File encoding support restored** — GBK/GB18030 (and other non-UTF-8) files
527 can now be read, edited, and grepped correctly. The v2 rewrite had dropped
528 v1's encoding detection; files in CJK Windows charsets were silently misread
529 or rejected as binary. The read/edit/write round-trip now preserves the
530 original file encoding. (#2637)
531
532 ### Notes
533
534 - Versions: the legacy TypeScript line stays in `0.x`; the Go line starts at
535 `1.0.0`. See [docs/MIGRATING.md](docs/MIGRATING.md).
536 - Release archives ship a bare binary; CodeGraph is fetched on first use. Windows
537 support for the fetched runtime is unverified — install `codegraph` on PATH if
538 the auto-fetch doesn't resolve there.
539
540 [1.20.0]: https://github.com/esengine/DeepSeek-Reasonix/releases/tag/desktop-v1.20.0
541 [1.0.0]: https://github.com/esengine/DeepSeek-Reasonix/releases/tag/v1.0.0
542
542 lines MARKDOWN