## 0.2.2 (2026-10-01)
### Features
#### Native OpenAI Responses computer use
Register the native `computer` tool for an explicitly bound CDP browser, execute
ordered action batches with retained per-thread sessions and cancellation
cleanup, and return original-detail `computer_screenshot` observations through
`computer_call_output`. Preserve native call identities through transcript
replay, WebSocket continuation, and ACP tool updates. Include an independent
real-browser protocol eval and a live OpenAI eval runner.
Accept the native API's nullable mouse modifiers. Initialize TLS and large
worker stacks in the live runner, preserve call execution order in its trace,
and independently verify the final browser UI and masked screenshot.
### Fixes
#### Preserve browser observations and execute Desktop input through CDP
Keep screenshot text and original resolution in Responses tool replay, including
when older images are removed to fit the request budget. Attach Chrome extension
screenshots to the model input. Use stable document-scoped refs, real CDP input,
validated typing targets, isolated script state, and explicit action failures in the Desktop fallback.
Isolate browser-use servers by thread, serialize actions with fresh page state,
and stop the owned process tree when an in-flight tool is cancelled. Cover
browser observations and permission rejection through the ACP transport.
Give each browser-use server a private profile and file directories, enforce
optional operator navigation ceilings, and bound agent steps. Preserve Desktop
tab identity across enumeration changes. Release held input and screenshot
masks on cancellation or failure, including sessions retained by their owner.
Cancel a pending Chrome bridge command on dispatch timeout or dropped futures,
and label the paired extension action observations as untrusted page data.
Support optional caller-defined Jev completion conditions checked against fresh
UI state. Reject premature model DONE and permit bounded fallback recovery;
report unverified model completion explicitly when no conditions were supplied.
## 0.2.1 (2026-09-28)
### Fixes
#### Format catalog imports
Formatting only; no behaviour change.
## 0.2.0 (2026-09-26)
### Breaking Changes
#### Release the Responses loop and Codex patch parity improvements as Roder 0.2, including dependent crates built against the new shared API. Isolate config-dependent tests from process environment and saved authentication. Update shell-include coverage to the current Plan process policy.
Breaking change: apply_patch accepts only the canonical patch argument and Codex patch syntax. Crate consumers must rebuild against the new shared API versions.
### Features
#### Align apply_patch parsing, ordered line matching, custom-tool grammar, model routing, and streamed input with Codex. Use one canonical patch argument and Codex patch syntax for local and remote tools. Fix split UTF-8 SSE decoding, terminal completion, client tool-search continuation contracts and exhaustion, replay, pooled HTTP transport, and Retry-After handling. Retry transient sampling failures across runtime profiles, stop on terminal completion, reject silent EOF, preempt sampling on steering, and emit terminal failures once.
Persist completed messages, reasoning, search exchanges and tool effects during sampling. Execute opted-in reads eagerly through normal policy and authorization checks. Add task-scoped WebSocket pooling with verified delta continuation, interruption invalidation and HTTP fallback. Add provider-native, task-aware compaction, complete opaque-window replay, request byte/image guards, failure identifiers, streamed proposed patch progress, actual filesystem diffs and uncertainty-aware partial outcomes and rollback.
Require canonical completion from mock tool responses and keep sampling steering separate from turn cancellation, including immediate-interrupt races. Keep manual compaction and new input atomic for its target task. Prevent concurrent eager reads from deadlocking streamed item persistence. Default new evaluation runs to GPT-6-luna.
## 0.1.22 (2026-09-26)
### Fixes
#### Publish today's content under fresh crate versions
`roder-api` 0.1.21, `roder-core` 0.1.19, `roder-app-server` 0.1.17,
`roder-evals` 0.1.2 and `roder-ext-openai-responses` 0.1.10 were published to
crates.io on 2026-09-23 from a branch that predates the Codex agent backend,
the Jev browser tool, the Chrome bridge work and the Grok 4.7 catalog entries.
crates.io versions are immutable, so those numbers cannot carry the current
code and the registry copies do not match the git tags of the same version.
Bump them so the released content reaches crates.io under versions that
describe it. `roder-ext-jev` and `roder-ext-codex-backend` are bumped with
them: both are new crates whose first publish must depend on a registry
`roder-api` that actually contains `roder_api::backend`, which the 0.1.21
registry copy does not.
Adds the package-local READMEs both new crates need to publish.
## 0.1.21 (2026-09-26)
### Features
#### Select Codex as a complete agent backend for Roder
Add an extension service for complete agent backends and a Codex app-server implementation. Roder app-server maps its thread, turn, streaming event, and approval APIs to Codex, so existing Roder clients and the TUI can use Codex as the agent runtime.
Refresh GPT-6 and Claude Opus 5.5/Sonnet 5 catalog entries and map Codex token usage into Roder's turn counters.
#### Per-turn OpenAI service tier (Fast mode), and GPT-6 Sol and Luna
A caller can now choose the OpenAI service tier for a turn.
`StartTurnRequest::service_tier_override` (for example `"priority"` for Fast
mode) is carried to every inference round of the turn as
`RuntimeHints::service_tier`. The OpenAI Responses provider sends it as the
top-level `service_tier` request field only on the OpenAI profile; OpenRouter,
xAI, and Fireworks never receive it. `None` keeps the provider default.
The tier OpenAI reports it actually served (`response.service_tier`) is recorded
on `TokenUsage::service_tier`, so a biller can tell a request that ran fast from
one that was downgraded to `"default"` under load. Both new fields are optional
and default to absent when older payloads are deserialized.
`StartTurnRequest` gains a public field, so code that builds it with a struct
literal must add `service_tier_override: None`.
The OpenAI/Codex catalog adds `gpt-6-sol` (efforts `low` through `max`, like
`gpt-6-astra`) and `gpt-6-luna` (efforts `low` through `max`, like
`gpt-5.6-luna`), so per-turn reasoning validation accepts them.
#### Add Grok 4.7 to the xAI and SuperGrok catalogs
`grok-4.7` (500k context, high reasoning by default) is now listed for both the
`xai` and `supergrok` providers and is their default model, matching xAI's
current published roster.
## 0.1.20 (2026-09-12)
### Features
- Add Codex-compatible local project hooks with lifecycle diagnostics and expandable TUI output.
#### Add GPT-6 Astra, Gemini 3.8 Flash, and Claude Fable 5.1
Expose `gpt-6-astra` (1.05M context, efforts up to `max`) on the OpenAI/Codex
catalog, `gemini-3.8-flash` on both the Gemini API and Vertex AI providers, and
`claude-fable-5-1` on the direct Anthropic provider and through the local Claude
Code harness. Provider defaults are unchanged.
Fable 5.1 rejects forced tool choice, so the Anthropic request mapping now sends
`tool_choice: auto` for that model instead of `any`/`tool`.
### Fixes
#### Add Gemini 3.7 Flash and Grok 4.6 to provider model catalogs
Expose Gemini 3.7 Flash and Grok 4.6 through native, Cursor, xAI, SuperGrok,
and OpenRouter integrations with provider-specific context windows and
reasoning controls. Retire Grok 4.5 and Grok Build from active catalogs.
## 0.1.19 (2026-08-06)
### Fixes
#### Fix DeepSeek thinking mode reasoning in Ctrl+P and tool rollouts
DeepSeek models advertise real thinking efforts again, stream
`reasoning_content`, send the DeepSeek `thinking` toggle, and pass CoT back on
tool-call turns.
## 0.1.18 (2026-08-05)
### Features
#### Add Ultra mode as a first-class multi-agent mode for any model
Make Codex Ultra's proactive multi-agent policy a concrete Roder mode
(`/ultra`, `thread/set_ultra_mode`, `settings/get.ultraMode`,
`ultra/modeChanged`), available for every model — not only Sol/Terra Ultra
reasoning effort. Sol/Terra Ultra effort still maps to max wire effort and
enables proactive multi-agent without requiring the mode flag.
Also: `task` / `agent_swarm` children inherit the parent thread's live
provider+model (so SuperGrok stays on grok-4.5), and lane `max_concurrent`
can be raised per request for large fanouts instead of hard-failing at the
old scout cap of 4.
## 0.1.17 (2026-08-04)
### Fixes
#### Recover from Grok prompt-length overflows and advertise xhigh
Detect xAI/Grok `maximum prompt length` (and related context-overflow) errors as
context-limit failures, then force-compact and retry the live turn in place
(with a second attempt that strips the last bulky item). Compaction summary
inference shrinks its head and falls back to deterministic summaries when the
summary request itself overflows. Grok reasoning catalogs now include `xhigh`.
## 0.1.16 (2026-08-03)
### Features
#### Add `/review`: a read-only review sub-turn with structured findings and pluggable review publishers
`/review` runs a detached, read-only reviewer over the working diff, a base
branch, a commit, or a free-form scope, and returns prioritized findings with
file/line locations. Findings render in a new TUI panel where they can be kept
or dropped, and are exposed over the app-server as `review/start`,
`review/publish`, and `review/publishers/list` plus `review/started`,
`review/completed`, `review/failed`, and `review/published` notifications.
Publishing goes through a new `ReviewPublisher` extension service. The
first-party `roder-ext-github-review` publisher submits findings as GitHub pull
request review comments over the `gh` CLI or the REST API, with diff-hunk
prefiltering and a dry-run mode. Configure it under `[review]` and
`[review.publishers.github]`. Each `[review.publishers.<id>]` block is stored
opaquely and parsed by the publisher's own crate, so adding a platform does not
change the core config types.
Also fixes `roder app-server`, which built its Tokio runtime in current-thread
mode. Providers that bridge a synchronous callback back into async work call
`tokio::task::block_in_place`, which panics outright on a current-thread
runtime, so the `claude-code` provider aborted the server on its first
Roder-executed tool call. The app-server now uses a multi-threaded runtime like
the TUI entry point.
## 0.1.15 (2026-07-23)
### Features
#### Add DeepSeek Platform inference provider
Adds first-class `deepseek` provider support labeled "DeepSeek Platform", using
DeepSeek's OpenAI-compatible Chat Completions API at `https://api.deepseek.com/v1`
with `DEEPSEEK_API_KEY` auth and built-in models `deepseek-chat`,
`deepseek-reasoner`, `deepseek-v4-flash`, and `deepseek-v4-pro`.
## 0.1.14 (2026-07-21)
### Fixes
#### Fix OpenCode DeepSeek multi-step tool rollouts
Refresh the OpenCode Zen model catalog (drop disabled free DeepSeek IDs, add
current free models and paid `deepseek-v4-flash` / `deepseek-v4-pro`), coalesce
parallel tool calls into valid chat-completions histories for longer DeepSeek
rollouts, and surface clearer OpenCode ModelError/CreditsError messages.
## 0.1.13 (2026-07-21)
### Fixes
#### Add provider-authoritative remote workspace execution leases
Allow remote runner providers to fence a complete multi-step workspace tool
execution across runtimes or replicas. Roder now bounds lease acquisition,
stops execution if the provider loses the fence, releases it on every normal
tool outcome, and refreshes command deadlines after waiting for the fence.
## 0.1.12 (2026-07-21)
### Features
#### Bound and cancel detached remote commands
Remote command requests can now carry a wall-clock process lease. Remote shell
and exec tools request provider cancellation when they time out or are dropped
by turn interruption instead of allowing detached work to continue.
The Blaxel runner starts every command as a uniquely named process with a
finite server-side keep-alive timeout, polls the process API for commands that
run beyond the synchronous 60-second window, advertises cancellation, and
force-kills the process group when Roder cancels the command.
#### Read lifecycle state without loading full threads
Thread stores can now load persisted extension state directly. Lifecycle-only
reads use that seam, so metadata-only thread reads do not need to project a
full event, turn, and item snapshot.
## 0.1.11 (2026-07-21)
### Features
#### Freeform apply_patch on the Responses custom-tool channel
Advertise `apply_patch` on the OpenAI Responses freeform/custom tool channel
(`type:"custom"`) for the gpt-5.5 family, matching the channel the model was
RL-trained to emit patches on. `ToolSpec` gains a `freeform_input_field` marker
(default `None`, so ordinary function tools are unchanged); the Responses
provider serializes marked tools as `type:"custom"`, parses `custom_tool_call`
outputs into the normal tool-dispatch path, and replays their results as
`custom_tool_call_output`. Non-gpt-5.5 models and every other provider keep the
JSON `type:"function"` shape. The `apply_patch` handler accepts both the JSON
`{ "patch": ... }` arguments and the raw freeform body.
#### Add bounded lifecycle recovery, cleanup proof, and shutdown diagnostics
Roder now persists redacted per-turn lifecycle records, reconciles interrupted
turns after restart, and reports bounded cleanup ownership rather than treating
an aborted runtime task as proof that provider work was reaped. Local process
tasks drain through graceful signal, forced kill, and reap; remote tasks use the
remote runner cancellation API; and the Claude Code provider uses a vendored SDK
cleanup path with offline real-child regression coverage.
The app-server adds lifecycle notifications, `runtime/drain`, and
`lifecycle/metrics`; the CLI and TUI expose durable recovery state. A shared
`[lifecycle]` configuration controls shutdown budgets, task policy, bounded
process diagnostics, and compatible legacy shutdown fallbacks.
#### Path-based `view_image` tool for vision tasks
Adds a native `view_image(path)` tool that mirrors Codex's semantics: it reads
an image file (png/jpeg/gif/webp, validated by magic bytes, capped at 10 MiB),
base64-encodes it, and returns it as an image content block in the tool result
so the model sees the pixels. It reads through the workspace backend, so it
works against both local and remote-runner workspaces.
- `roder-tools`: new `view_image` tool (registered alongside the builtin coding
tools); a `read_bytes` method on the workspace backend for binary reads; and
`media_attach` now degrades to actionable guidance (pointing at `view_image`)
instead of hard-failing when called without raw base64 bytes, so it no longer
burns the consecutive-tool-failure budget in headless/eval runs.
- `roder-api`: `VIEW_IMAGE_DISPLAY_KEY`, a reserved `display_payload` key that
carries the image block from tool result to provider.
- `roder-ext-openai-responses`: `function_call_output` now forwards a
`view_image` result as an `input_image` content block (when the model
supports images), falling back to the plain string output otherwise.
### Fixes
#### Fix provider compaction thrashing and show token/duration summaries
Persist OpenAI/Codex compaction items as soon as the stream emits them so a
later SSE decode failure cannot drop the boundary and re-compact every round.
Surface before/after estimated tokens and elapsed time in the TUI and
app-server item stream.
#### Clarify subagent role selection and native full-history labels
Model-facing subagent tools now advertise configured roles, reject lane names
used as roles before fanout, and report lane/tool incompatibilities before a
child agent runs. Native `spawn_agent` full-history forks now accept their
advisory `agent_type` label while continuing to reject model, provider, and
reasoning overrides.
## 0.1.10 (2026-07-10)
### Features
#### Match Codex V2 Ultra agent lifecycle semantics
#### Added
- Added Codex V2-style canonical agent trees, full/empty/last-N context forks,
nested agents, reusable follow-up turns, mailbox-aware waiting, and
non-destructive interruption.
- Added exact parent model, provider, Ultra reasoning, workspace, policy, tool,
runner, and live developer-context inheritance for spawned agents.
- Added full `team/started`, `team/member/started`, and terminal result details
to the app-server protocol.
#### Changed
- `send_message` now queues coordination without starting an idle agent, while
`followup_task` starts or steers the existing canonical agent thread.
- Child final results and terminal errors are delivered automatically to their
direct parent, and completed identities remain available for later work.
- Inter-agent delivery now uses typed `MESSAGE`, `NEW_TASK`, and `FINAL_ANSWER`
envelopes with canonical sender and recipient paths.
#### Fixed
- Fixed spawn-capacity, completion/follow-up, interruption, mailbox batching,
acknowledgement, restart, and wait races found by comparison with Codex V2
and Claude Code agent workflows.
- Prevented full-history children from replaying parent orchestration by making
the newest `NEW_TASK` payload the authoritative child assignment.
- Preserved spawn-time live instructions, developer context, and model
selection across reusable follow-up turns.
- Prevented interrupted-turn mailbox reservations from stranding queued
messages or accepting stale delivery acknowledgements.
- Bounded recursive agent paths to five levels below `/root`, rejecting deeper
spawns before creating team or thread state.
## 0.1.9 (2026-07-09)
### Features
#### Add GPT-5.6 Codex models and Ultra mode
Expose GPT-5.6 Sol, Terra, and Luna plus GPT-5.4 in the OpenAI and Codex
catalogs, with the current context windows, defaults, and reasoning-effort
menus. Make Sol the default Codex model.
Keep Ultra as a first-class Roder effort for Sol and Terra while mapping it to
the provider's `max` wire effort. Ultra enables proactive, bounded multi-agent
delegation; lower Sol and Terra efforts remain explicit-request-only.
## 0.1.8 (2026-07-09)
### Features
#### Add Grok 4.5 to xAI and SuperGrok providers
Expose `grok-4.5` (500k context, default high reasoning, low/medium/high) as the
default model for both the `xai` API-key provider and SuperGrok OAuth. Keep
legacy Grok 4.3 / 4.20 and SuperGrok Build/Composer entries selectable.
## 0.1.7 (2026-07-01)
### Features
#### Add Claude Fable 5 to the Cursor provider catalog
Expose `claude-fable-5` (1M context, full effort range including `xhigh`/`max`,
default `high`) as a Cursor AgentService-routed model, matching the Anthropic
and Claude Code catalog entries so Fable 5 is selectable across all three
providers.
## 0.1.6 (2026-06-30)
### Features
#### Blaxel sandbox runner with pause, resume, detach, and rejoin
Replace the placeholder Blaxel runner passthrough with a first-party Blaxel
Sandboxes provider that drives the real control-plane (`/sandboxes`) and
per-sandbox (process/filesystem/preview) REST APIs.
The remote-runner contract gains optional, defaulted lifecycle support so a
runner-bound thread can pause its sandbox toward standby, resume it, fully
detach (releasing the local session while keeping the sandbox alive), and
rejoin the same sandbox from persisted thread state — including across a
process restart, with no orphan sandbox creation. New `RunnerCapabilities`
flags (`pausable`, `detachable`) and `RemoteRunnerSession`/`RemoteRunnerProvider`
methods (`pause`, `resume`, `detach`, `rejoin_session`) default to no-op/false so
existing providers are unchanged.
Exposed through new app-server JSON-RPC methods (`runners/pause`,
`runners/resume`, `runners/detach`, `runners/rejoin`) and a `roder runners` CLI.
The Blaxel credential is sourced from the environment (`BLAXEL_API_KEY` /
`BL_API_KEY`, with `BL_WORKSPACE`) and never written to session state.
A selected runner now actually routes coding tools into the sandbox: a
runtime-level destination (TUI runner picker or config `default_destination`)
auto-binds new threads when the provider advertises a default workspace via the
new `RemoteRunnerProvider::default_workspace` (Blaxel opts in; other providers
are unchanged). Verified live end to end against a real Blaxel account: TUI
shell/file tools execute inside an Alpine sandbox, and pause/resume/detach/rejoin
work through the CLI.
## 0.1.5 (2026-06-26)
### Features
#### Global agent-swarm rate-limit capacity governor
Add the global capacity-shrink / quiet-window recovery throttle for the
`agent_swarm` scheduler (roadmap 104, Task 3 follow-up), so a swarm backs off as
a whole under sustained provider rate limits instead of every child retrying in
parallel with only per-child backoff.
A shared `RateLimitGovernor` is inert until the first provider rate limit. On the
first rate limit it sizes a global capacity from the children that were active
when it hit, then shrinks by one; later rate limits shrink by one more (floor of
one) no more often than `rate_limit_shrink_interval_ms` (default 2000), and
launches are paced apart while throttled. After a quiet
`rate_limit_recovery_interval_ms` (default 180000, three minutes) with no rate
limit, the swarm recovers one unit of capacity. The normal-phase ramp, overlap,
ordering, and `max_concurrency` cap are unchanged.
New bounded config knobs (`[agent_swarm].rate_limit_shrink_interval_ms`,
`rate_limit_recovery_interval_ms`) and matching
`RODER_AGENT_SWARM_RATE_LIMIT_SHRINK_INTERVAL_MS` /
`RODER_AGENT_SWARM_RATE_LIMIT_RECOVERY_INTERVAL_MS` env overrides resolve the
windows. Covered by fake-clock (`tokio::time::pause`) tests for shrink, recovery,
and a sustained-rate-limit end-to-end run that completes in order without
deadlock.
#### Live agent_swarm progress events
Emit an `AgentSwarmProgress` `RoderEvent` each time a swarm child resolves,
carrying a running `completed/failed/aborted/total` snapshot (roadmap 104,
Task 1 follow-up). This lets a client render a live "N/total done" tick between
`AgentSwarmStarted` and `AgentSwarmCompleted` instead of only the final result.
The scheduler reports incremental progress through a new
`AgentSwarmProgressObserver`; the `agent_swarm` tool bridges it onto a runtime
`AgentSwarmProgressSink` supplied on the tool-execution context, which the
runtime backs with the event bus (and thread-event persistence). Children do
not publish progress; only the lead swarm does.
## 0.1.4 (2026-06-26)
### Features
#### Agent-swarm mode
Add a Roder-native `agent_swarm` fanout tool and `/agent-swarm` (alias `/swarm`)
commands (roadmap phase 104). A lead model can launch many homogeneous
subagent tasks from one `prompt_template` (with the `{{item}}` placeholder) over
an `items` array, optionally resuming existing agents via `resume_agent_ids`,
and receives an ordered `<agent_swarm_result>` summary with completed/failed/
aborted counts and resumable agent ids. A bounded scheduler paces launches
(initial burst then one per interval), honors an optional concurrency cap,
preserves input order, and supports cooperative cancellation. Configure via
`[agent_swarm]` or `RODER_AGENT_SWARM_*` env. The `/agent-swarm on|off|status`
command toggles a persistent swarm reminder; `/agent-swarm <prompt>` runs one
swarm task.
#### Enforce agent_swarm as the only tool call in a response
The core turn loop now denies any model response that mixes `agent_swarm` with
other tool calls, or issues multiple `agent_swarm` calls at once (roadmap 104,
Task 2). Each call in the offending batch gets an error tool result with
actionable retry text, so the model re-issues `agent_swarm` by itself and every
`tool_call_id` still receives a response (keeping chat-completions transcripts
valid). Adds `roder_api::subagents::agent_swarm_batch_violation` and the shared
`AGENT_SWARM_TOOL_NAME` constant.
#### Agent-swarm lifecycle events on the event bus
Emit `AgentSwarmStarted` (with the child count) and `AgentSwarmCompleted` (with
completed/failed/aborted counts) `RoderEvent`s when the `agent_swarm` tool runs,
so any app-server/SDK/TUI client can observe a swarm as a whole rather than only
the per-child `Subagent*` traces (roadmap 104, Task 1). The runtime emits these
around tool routing; existing notification mappers fall through their catch-all
arms, so no client breaks.
#### Server-side agent-swarm mode
Move agent-swarm mode from TUI-only client state to runtime/app-server state so
every client benefits (roadmap 104). Adds the `thread/set_agent_swarm_mode`
app-server method, an `agentSwarmMode` field on `settings/get`, and an
`AgentSwarmModeChanged` event. When swarm mode is active the runtime injects the
canonical swarm reminder into each turn's developer instructions
(`Runtime::set_agent_swarm_mode` + `apply_agent_swarm_mode`), so the model is
nudged toward the `agent_swarm` fanout tool regardless of which client drove the
turn. The TUI now toggles swarm mode through the method and no longer prepends
the reminder client-side. Also fixes two pre-existing method-manifest ordering
issues (`auth/kimi-code/*`, `thread/compact`).
#### Rate-limit-aware agent_swarm scheduling
Swarm children that fail with a provider rate limit are now requeued with
exponential backoff (default 3s, 6s, 12s, ... up to 4 retries) instead of
failing outright (roadmap 104, Task 3). The concurrency permit is held across
the backoff so a rate-limited swarm naturally throttles rather than hammering
the provider, and cancellation still wins promptly. Tunable via
`[agent_swarm].rate_limit_max_retries` / `rate_limit_base_backoff_ms` and the
`RODER_AGENT_SWARM_RATE_LIMIT_*` env vars (retries are clamped to a hard cap so
a swarm can never wait unboundedly).
#### Per-thread MCP bearer token
Let a remote client scope a thread's MCP tool calls to a specific identity (for
Vex: a per-user, per-organization capability token). The client forwards the
token via a new `mcpAuthToken` field on `thread/start`; the app-server records
it in an in-memory `roder_api::mcp_auth` registry keyed by thread id, and the
MCP tool extension reads it during execution to authenticate that thread's tool
calls (falling back to the process default when absent). Tokens are short-lived
and re-supplied on each `thread/start`.
#### Subagent and swarm children inherit the parent workspace
Subagent (`task`) and agent-swarm children built their tool-execution context
with no handles, so any child file/shell/search tool failed with "workspace
handle is not available" and the child could not do real work. Children now
inherit the lead turn's workspace, remote workspace, process runner, and
context-artifact handles via the new `SubagentDispatcher::dispatch_with_context`
(the parent goal controller and trace sink are intentionally not inherited).
Each child still runs on its own child thread/turn id, so it operates on the
same repository as an independent agent rather than being confused with the
main-line thread.
### Fixes
#### Cursor fast variants, reasoning params, and stable conversation ids
Expose `composer-2.5-fast` and `gpt-5.5-fast` as first-class catalog models, encode AgentService `fast`/`effort`/`thinking` params from Roder reasoning config, reuse a stable per-thread Cursor `conversation_id`, and open the reasoning submenu when selecting Cursor models that advertise effort options.
## 0.1.3 (2026-06-22)
### Features
#### Add first-party Synthetic inference provider
Adds the `synthetic` provider using Synthetic's OpenAI-compatible Chat
Completions API. The provider ships built-in `syn:` model aliases
(`syn:large:text` default, plus `syn:small:text`, `syn:large:vision`,
`syn:small:vision`), preserves concrete `hf:{owner}/{model}` ids across config,
discovery, and selection, and resolves credentials only from
`SYNTHETIC_API_KEY`/`RODER_SYNTHETIC_API_KEY` or `[providers.synthetic]`. The
provider is visible without credentials so app-server and TUI can show setup
state, and turn-time inference fails locally with setup guidance when the key
is missing. The TUI provider menu points to the Synthetic dashboard for API-key
setup instead of the generic fallback URL.
### Fixes
#### Fix grok-composer-2.5-fast image input handling
The `grok-composer-2.5-fast` model does not support image inputs, but Roder's catalog
hardcoded `supports_images: true` for all xAI/SuperGrok models. The `xai_model` macro now
takes a `supports_images` parameter so non-vision models can correctly declare their
capabilities.
The OpenAI Responses provider engine now checks the model's `supports_images` flag before
emitting `input_image` content items in request payloads. This prevents the xAI API error:
"Image inputs are not supported by this model."
`grok-composer-2.5-fast` is set to `supports_images: false`; all other Grok models keep
their previous `true` value.
## 0.1.2 (2026-06-16)
### Features
#### Fireworks AI inference provider
Add the first-party `fireworks` inference provider with account-scoped model ids, Fireworks-specific API-key configuration, OpenAI-compatible Responses transport, offline model metadata, model discovery, and app-server provider-list coverage.
### Fixes
- Improve context compaction across phases 2–4: prune old tool outputs before full compaction, add LLM state-snapshot summarization with verify/reject, hysteresis coalescing, `/compact` via `thread/compact`, `context.compaction_skipped` metrics, and a Grok-style loop regression fixture. Phase 1 fixes remain: compaction boundary on load, once-per-turn guard, ProviderMetadata exclusion from token estimates, and suffix retention from the last user message.
- SuperGrok now lists only Grok Build 0.1 (500k context) and Grok Composer 2.5 Fast (200k context), with curated catalog metadata instead of raw xAI /models discovery.
#### Added first-class `kimi-code` (aliases: `kimi`, `moonshot`) inference provider and `roder-ext-kimi-code` crate.
- Kimi Code subscription OAuth uses the managed API (`api.kimi.com/coding/v1`) with Kimi device headers and `kimi-code-cli` User-Agent; API keys still use Moonshot Open Platform (`api.moonshot.ai/v1`).
- Catalog entry + `kimi-for-coding` model (K2.7 Code).
- Device OAuth against `auth.kimi.com` with `roder auth login kimi-code`, TUI/app-server `auth/kimi-code/*`, and token storage under `~/.roder/auth/kimi-code.json`.
- API key fallback via env/config (`KIMI_CODE_API_KEY`, `RODER_KIMI_CODE_API_KEY`).
- Registered via extension host (always available, like SuperGrok).
- Docs: `docs/roder-kimi-code-provider.md`.
- Live smoke test added (opt-in via `RODER_KIMI_CODE_LIVE=1`).
## 0.1.1 (2026-06-15)
### Features
#### First-party image generation providers (OpenAI GPT Image and Google Gemini Nano Banana)
Provider-neutral image generation through the core media API: an image-capable
`MediaGenerationRequest`/multi-output `MediaGenerationResponse` contract, a new
`ProvidedService::MediaGenerator` extension service, a runtime media generation
service backing the canonical `media_generate_image` tool with a deterministic
offline fallback, new `roder-ext-openai-images` (`gpt-image-2` plus legacy ids)
and `roder-ext-google-images` (Nano Banana 2/Pro/base) provider crates,
`[media.image_generation]` config, `media/image/providers/list` and
`media/image/generate` app-server methods, `roder media` CLI commands, palette
entries, and regenerated schemas/SDK stubs. Live provider smokes stay opt-in
behind `RODER_OPENAI_IMAGE_LIVE` / `RODER_GEMINI_IMAGE_LIVE`.
#### One-command Roder package install (`roder install npm:/git:/path`)
Roder packages bundle process extensions, skills, slash commands, and themes
behind a root `roder.toml` manifest. Install from npm, git (shorthand, SSH,
raw URLs, pinned refs), or local paths; manage with `roder packages
list|resources|enable|disable|approve|filter|sync|init`, `roder remove`,
`roder update`, and ephemeral `-e` loading. Resources surface through the
existing skills/commands/theme registries; the process-extension protocol
gains manifest-declared tool providers served over `tools/call`. New
app-server `packages/*` methods, a `/packages` builtin, and a Packages
palette section round out the surfaces. npm lifecycle scripts stay disabled
unless `--allow-scripts` is passed, and package process extensions never
launch before explicit approval.
### Fixes
#### Process-extension protocol 0.2.0 and Cursor SDK remote-agent bridging
Extend the process-extension protocol with subagent-dispatcher and task-executor services, bridge them in the process host, and add app-server e2e coverage for the cursor-sdk-agents TypeScript child.
#### Package-specific registry READMEs
Add package-specific README files for every Cargo crate, ensure npm and PyPI package READMEs link to roder.sh, and tighten the registry README verifier to require package-local documentation.
#### Registry README metadata and publish checklists
Ensure Cargo crates inherit the workspace README, document npm and PyPI publishing steps in package READMEs, and add a registry README verifier for future publishes.
#### SuperGrok: default to grok-build-0.1, add it to catalog, enable live /models discovery
- Change SuperGrok provider default_model to `grok-build-0.1`.
- Add `grok-build-0.1` (Grok Build) model entry under the `supergrok` provider (rich xAI capabilities: tools, structured, images, configurable reasoning; 256k ctx).
- `SuperGrokEngine::list_models` now plugs into the shared OpenAI-compatible `/models` + `/v1/models` discovery (using the live SuperGrok OAuth access token for Bearer auth). It uses the standard `~/.roder/models-cache.json` (respects RODER_MODELS_* envs for TTL/refresh/path), background refresh on stale, and falls back to the (now updated) static catalog on no-auth or error. This lets Roder surface the latest models and (basic) capabilities from xAI for SuperGrok subscribers without requiring Roder releases.
- Exposed the reusable `discover_models`, `cached_models`, `save_cached_models`, `cache_ttl`, `force_refresh_requested`, and `CachedProviderModels` from `roder-ext-openai-responses` (pub) so other xAI-flavored paths can reuse.
- Updated tests, docs, and examples to reference `grok-build-0.1` for SuperGrok. (Composer 2.5 remains a Cursor-native model.)
- Live validation with real SuperGrok token confirms `/models` returns (among others) `grok-build-0.1` + current Grok variants.