Hmbown/CodeWhale
48.3
Weak · 7 August 2026
6k
lines of production code
3
measurements over time
What this system is
This release delivers a comprehensive architectural overhaul, replacing the legacy core engine and TUI with a new modular, event-driven runtime and a feature-rich terminal interface. Key additions include a centralized model registry, a structured hook system, and a robust work graph for session management. The TUI has been significantly expanded with new slash commands for memory, fleet, and plugin management, alongside a new embedded web client and improved theme system. The release also introduces new integrations for Telegram, Feishu, and WeChat, while removing deprecated npm and Python wrappers in favor of native distribution methods.
Features
Add @codewhale/runtime-sdk for local Fleet management
The npm/runtime-sdk package now provides a JavaScript/TypeScript client for Codewhale's local Runtime API. It exposes helpers to create, start, stop, and restart Fleet runs and workers, as well as stream or replay Fleet events. The SDK enforces that creation requests must specify roles, a parallel workflow, and the 'this\_computer' target; other targets fail closed. It also introduces a RuntimeCapabilityError for missing API endpoints.
npm/runtime-sdk · high confidence
Add Codewhale install script for macOS and Linux
Users can now install Codewhale via a new shell script (install.sh) that automatically detects the user's platform (macOS or Linux) and downloads the appropriate prebuilt binary. The script supports environment variables to customize the install directory, select a specific release version, or skip the glibc compatibility check on Linux arm64 systems.
web/public · high confidence
Add Models & providers page with dynamic provider registry
A new Models & providers page has been added to the web app, featuring a dynamically generated list of supported provider routes. The page displays each provider's ID, label, and associated environment variables, with content localized for English and Chinese. It also includes configuration guidance for DeepSeek, local runtimes (vLLM, SGLang, Ollama), and OpenRouter, alongside links to the full provider documentation and installation instructions.
web/app/\[locale\]/models · high confidence
Add Nix package for the Codewhole CLI
A new Nix package definition (package.nix) has been added to build the Codewhole CLI. This includes build and test dependencies such as OpenSSL, D-Bus, and Python, and configures the check phase to run tests in a sandboxed environment with appropriate library paths and environment variables.
nix · high confidence
Add OpenAI-compatible /v1/chat/completions endpoint
The app-server now exposes a new \/v1/chat/completions\ HTTP endpoint that accepts OpenAI-compatible request bodies and forwards them to the configured provider. This allows clients to interact with the system using standard OpenAI API formats, with the server handling model resolution, provider configuration, and header forwarding.
crates/app-server · high confidence
Add Tencent Lighthouse deployment templates and systemd services
Added new deployment templates and configuration files for deploying CodeWhale on Tencent Lighthouse. This includes CNB (Cloud Native Build) pipeline templates for automated builds and deployments, systemd service units for the runtime API, Feishu bridge, and Telegram bridge, along with example environment files for each component. These files provide the necessary infrastructure to run CodeWhale components as managed services on a remote Lighthouse instance.
deploy · high confidence
Add WeCom (企业微信) bridge for smart bot integration
Users can now connect CodeWhale to WeCom (企业微信) via a new bridge that uses the WeCom Smart Bot API (WebSocket long-connection mode) to interact with the local CodeWhale runtime. The bridge requires BotID and Secret credentials, supports chat/user allowlists for security, and enables natural-language approval responses for tool calls. This integration allows remote terminal agent interaction without exposing a public IP.
integrations/wecom-bridge · high confidence
Add Weixin Bot Bridge for personal WeChat account integration
Introduces a new Weixin Bot Bridge integration that connects personal WeChat accounts to the CodeWhale runtime using the iLink Bot protocol. Users can now log in via QR code scan, enabling direct private chat interactions with the AI assistant. The bridge supports message types including text, images, voice, and files, and provides commands for thread management, model selection, and tool approval. Configuration is handled via environment variables (e.g., WEIXIN\_CHAT\_ALLOWLIST) and a .env.example template is provided for setup.
integrations/weixin-bridge · high confidence
Add \`codewhale remote-setup\` wizard for generating remote agent deploy bundles
Users can now run \codewhale remote-setup\ to generate a self-contained deploy bundle for a remote agent. The wizard collects a cloud target, a chat bridge, and a model provider, then renders environment files, systemd units, and a RUNBOOK to a specified output directory. This is a generate-only MVP; the \--apply\ auto-provision path is currently stubbed.
_crates/tui/src/remote\setup · high confidence
Add a localized Contribute page with step-by-step contribution guidelines
A new Contribute page has been added at web/app/\[locale\]/contribute, providing users with structured, localized instructions on how to file issues, submit pull requests, improve documentation, and review existing work. The page includes a four-step workflow for contributing code and a section detailing the pull request process, with content available in both English and Chinese.
web/app/\[locale\]/contribute · high confidence
Add admin API endpoints for login, logout, and post management
The admin API now includes new endpoints for authentication and content management. The login route (/api/admin/login) validates a maintainer token and issues an HTTP-only, secure session cookie (mt\_sid). The logout route (/api/admin/logout) invalidates the session and clears the cookie. The post route (/api/admin/post) allows authenticated users to post or discard drafts, with strict validation of the request origin, payload size, and action type. For 'post' actions, it interacts with the GitHub API to create issues or comments, marking drafts as posted in the KV store.
web/app/api/admin · high confidence
Add constitution thesis page
A new /constitution page has been added to explain the three-layer constitution system (bundled base law, user standing law, and repo-specific law) and how the execution framework enforces their priority. The page includes a thesis section, a breakdown of the three layers with their respective paths and descriptions, and a demonstration of the model's reasoning using the ThinkingTrace component.
web/app/\[locale\]/constitution · high confidence
Add dynamic GitHub feed API endpoint
A new public API route at /api/github/feed has been introduced to serve a GitHub feed. The endpoint fetches the latest 50 items and returns them as JSON, with a 10-minute revalidation period. This change ensures the feed remains dynamic and up-to-date for users.
web/app/api/github · high confidence
Add image analysis tool for vision models
Users can now use the new \image\_analyze\ tool to send images to an OpenAI-compatible vision model API and receive text descriptions. The tool supports PNG, JPEG, GIF, WebP, and BMP formats, and includes path-traversal protection to ensure images are read only from within the workspace directory.
crates/tui/src/vision · high confidence
Add interactive FAQ page with search and structured Q&A
A new FAQ page is introduced at the /faq route, featuring a searchable list of frequently asked questions about Codewhale's installation, configuration, provider support, and operational modes. The page dynamically renders content based on the user's locale (English or Chinese) and includes specific guidance on API key setup, supported providers (including OpenRouter and self-hosted models), and the differences between Plan, Act, and Operate modes.
web/app/\[locale\]/faq · high confidence
Add multilingual install and verification page
A new install page is introduced at web/app/\[locale\]/install/page.tsx, providing step-by-step installation, verification, and update instructions for Codewhale. The page supports both English and Chinese (zh) locales, displaying shell scripts, npm, Cargo, Homebrew, Docker, and source build commands. It also includes a configuration tree structure and verification steps using codewhale doctor, ensuring users can easily install and validate their setup.
web/app/\[locale\]/install · high confidence
Add new CLI entry points for CodeWhale
New executable scripts have been added to the npm package, providing dedicated entry points for the CodeWhale CLI. Users can now invoke the application via the 'codew' and 'codewhale' commands, each wrapping the corresponding internal run functions to start the respective interfaces.
npm/codewhale/bin · high confidence
Add redirect worker to route traffic to codewhale.net
A new Cloudflare Worker has been added to handle HTTP redirects. The worker intercepts requests to deepseek-tui.com and www.deepseek-tui.com, performing a 301 permanent redirect to codewhale.net. This is configured via a new \web/redirect\ directory containing the worker logic and Wrangler configuration.
web/redirect · high confidence
Add remote-smoke lab scripts for provisioning and running a headless agent loop
The \scripts/remote-smoke\ directory now contains a complete, experimental smoke-lab for the US-first remote-workbench lane. It includes provider-agnostic setup and teardown scripts for AWS Lightsail and DigitalOcean, a shared \setup-vm.sh\ that installs prebuilt CodeWhale binaries, the Telegram bridge, and the \gh\ CLI, plus an \agent-session.sh\ helper. The README documents the security model, cost, and the autonomous agent loop that picks issues, creates PRs, and handles blockages headless.
scripts/remote-smoke · high confidence
Add support for the xAI provider via OAuth device-code flow
Users can now connect their xAI account to the application using the OAuth device-code flow. This enables access to xAI models through the standard provider configuration interface, allowing users to route requests to xAI's infrastructure alongside other supported providers.
(repo-wide) · high confidence
Add weekly community digest archive page
A new page at /digest/\[locale\] displays an archive of weekly community updates. The page fetches data from a KV store, parses each entry independently to prevent a single malformed record from breaking the entire list, and renders a bilingual (English and Chinese) list of digest articles with titles, summaries, and sections. The page includes metadata for SEO and handles empty states gracefully.
web/app/\[locale\]/digest · high confidence
Added 'codew' convenience alias for the CLI
Users can now invoke the CLI using the shorter 'codew' command, which acts as a shim that forwards arguments to the main 'codewhale' dispatcher. This new binary is installed alongside the main executable, preferring the dispatcher in the same directory before falling back to the system PATH, providing a shorter entry point for the same functionality.
crates/cli/src/bin · high confidence
Added Codewhale telemetry crate for anonymous usage reporting
A new \crates/telemetry\ crate has been introduced to handle anonymous usage statistics. It implements a background writer that buffers events to disk and flushes them to a first-party ingest endpoint, with a fallback dry-run sink for local testing. The system enforces strict privacy boundaries: it collects only aggregated counts, OS/architecture metadata, and session durations, while explicitly excluding prompts, code, file names, and credentials. Users are prompted on first run to opt-in, and can disable telemetry at any time via configuration or environment variables.
crates/telemetry · high confidence
Added OpenHarmony (OHOS) clang/clang++ wrapper scripts for Windows and Unix
New shell and PowerShell wrapper scripts (ohos-clang, ohos-clangxx) have been added to the build system to invoke the OpenHarmony native SDK's clang and clang++ compilers. These scripts validate the OHOS\_NATIVE\_SDK environment variable and ensure the LLVM binaries and sysroot are present before execution. On Windows, the wrappers specifically handle argument quoting to prevent spaces in paths (such as those in DevEco Studio directories) from breaking the linker invocation.
scripts/ohos · high confidence
Added automated setup and validation scripts for Tencent Lighthouse deployments
New shell scripts have been introduced to automate the deployment and health-checking of CodeWhale services on Ubuntu. The \bootstrap-ubuntu.sh\ script handles initial server configuration, including installing system dependencies, creating the \codewhale\ user, setting up directory structures, cloning the main repository, and generating default environment files for the runtime and Feishu/Telegram bridges. The \install-services.sh\ script automates the installation of systemd units for the runtime and selected bridge, copying bridge code and installing environment templates. The \doctor.sh\ script provides a comprehensive diagnostic tool that checks for required tools (Node.js, Git, etc.), validates environment file permissions and content, and verifies the state of the workspace and binaries. These scripts streamline the process of getting a Tencent Lighthouse instance running and provide a way to verify the installation.
scripts/tencent-lighthouse · high confidence
Centralized model registry with unified resolution and capability flags
The agent crate now uses a centralized \ModelRegistry\ that maps user-facing model names and aliases to concrete provider-specific model entries. This new resolution system supports tool use and extended reasoning capability flags, and includes built-in entries for DeepSeek, NVIDIA NIM, OpenAI, and AtlasCloud models, allowing users to reference models by various aliases or explicit IDs.
crates/agent · high confidence
Feishu bridge now supports per-chat model switching and thread-scoped replies
The Feishu bridge now supports per-chat model switching via the /model command, allowing users to select specific models for individual chats. The bridge also replies within the same Feishu thread/topic instead of creating standalone topics, preserving conversation context. Configuration is managed via CODEWHALE\\ environment variables (with DEEPSEEK\\ fallbacks for legacy deployments), and a new validate-config script verifies environment and filesystem settings.
integrations/feishu-bridge · high confidence
Improved LLM client error handling and testability
The LLM client now provides richer authentication error context, including provider, base URL, model, and key details, to help diagnose connection failures. Additionally, a new \MockLlmClient\ implementation allows tests to queue canned responses and assert on outgoing requests, while error classification distinguishes transient failures (retryable) from durable ones like quota exhaustion or authentication errors (non-retryable).
_crates/tui/src/llm\client · high confidence
Introduce Agent Plugins v1.0.0 support for discovering, validating, and exporting plugin bundles
The TUI now supports the Agent Plugins v1.0.0 format, allowing the system to discover, parse, and validate plugin bundles containing a \plugin.json\ manifest, an optional \mcp.json\ for MCP servers, and a \skills/\ directory. This change adds a new plugin registry that manages plugin state, trust, and enablement, while also providing an export mechanism to publish plugins as spec-valid bundles. The implementation includes strict validation of plugin names, content hashes, and file system paths, ensuring that only reviewed and trusted plugins are enabled.
crates/tui/src/plugins · high confidence
Introduce CodeWhale VS Code extension scaffold for local runtime integration
The \extensions/vscode\ directory now contains the initial scaffold for the CodeWhale VS Code extension. This adds a read-only Agent View that displays recent runtime thread summaries and restore points, with automatic refreshes configurable via \codewhale.agentViewRefreshIntervalSeconds\. The extension also provides commands to open a local runtime terminal, start the runtime, and manually refresh the view. It is a local development scaffold that does not yet expose the full chat webview, editor integration, or marketplace publish workflow.
extensions/vscode · high confidence
Introduce Codewhale account management and secure credential handoff
The CLI now supports managing a managed Codewhale account and storing provider API keys in a remote vault via the new \codewhale cloud\ subcommand (login, status, logout, and key management). Additionally, a new \codewhale metrics\ command aggregates usage data from audit logs, sessions, and runtime events. For secure operations, the CLI now uses a dedicated \credential\_handoff\ module to safely pass secrets to child processes via pipes, ensuring sensitive data is never printed to the terminal.
crates/cli/src · high confidence
Introduce Codewhale harness adapter for Verifiers
Users can now run Codewhale as a harness for the Verifiers framework, enabling isolated rollouts with bounded terminal receipts and strict environment separation. The adapter pins Codewhale to version 0.9.4, intercepts model traffic through Verifiers' endpoints, and ensures that sensitive data like session secrets are never passed in command-line arguments or receipt metadata.
integrations/verifiers-codewhale · high confidence
Introduce Hotbar Action Registry and Setup Wizard
The TUI now features a structured Hotbar Action Registry that categorizes actions (App, Route, Slash, Mcp, Skill, Plugin) with metadata, safety classes, and recommendation levels. This infrastructure powers a new Hotbar Setup Wizard, allowing users to configure and assign hotbar slots through an interactive, localized interface. The change also introduces a \HotbarDispatch\ enum to handle action outcomes, supporting both direct app state mutations and event loop actions.
crates/tui/src/tui/hotbar · high confidence
Introduce Lane runtime and control-plane contract
Adds the \crates/lane\ module, establishing a typed control-plane contract for managing Lane lifecycle (start, stop, reconcile) and a durable registry for Lane records. It introduces runtime backends (tmux, inline, VM, CI) to execute workflows, manages isolated git worktrees for each Lane, and enforces a unified command interface for CLI and TUI surfaces.
crates/lane · high confidence
Introduce Telegram bridge integration for CodeWhale runtime control
Users can now control a local CodeWhale runtime via Telegram. The new bridge uses long-polling to receive messages and send updates, supporting private chats and optional group chat control with a configurable prefix. It exposes commands (/menu, /status, /threads, /new, /interrupt, /compact, /allow, /deny) and inline buttons for actions. The bridge enforces a chat allowlist (with a temporary unlisted pairing mode) and handles MarkdownV2 formatting with plain-text fallbacks. Configuration is managed via environment variables (e.g., TELEGRAM\_BOT\_TOKEN, TELEGRAM\_CHAT\_ALLOWLIST) and validated by a dedicated config validation script.
integrations/telegram-bridge · high confidence
Introduce a canonical locale registry and deterministic detection for the website
The website now uses a single source of truth for all supported languages, defining each locale's status (shipped, partial, planned, or deferred) and providing a robust detection system. Users will see a new language switcher that supports 11 languages, including 8 new partial translations for the site's chrome and home page. The system automatically detects the user's preferred language from browser headers or cookies, falling back to English if no match is found. This change ensures that all routed locales have consistent navigation and footer links, and that partial translations are clearly marked.
web/lib/i18n · high confidence
Introduce background advisor and structured sub-agent coordination tools
Adds a new background advisor feature that periodically reviews recent tool calls and emits concise, rate-limited advisory notes to the UI. Simultaneously, the sub-agent system is refactored to use a new mailbox abstraction for progress and state updates, and introduces a set of narrow coordination tools (agents/list, agents/message, agents/followup, agents/interrupt, agents/coordinate, agents/wait) that wrap the existing sub-agent runtime without restoring the older lifecycle tools. The sub-agent naming system is also updated to use locale-aware whale nicknames for better user-facing identification.
crates/tui/src/tools/subagent · high confidence
Introduce consent-gated external MCP imports and secure transport layers
The TUI now discovers external MCP server configurations from well-known locations (such as \\~/.claude.json\, project \.mcp.json\, and marketplace manifests) and presents them as import candidates. Users must explicitly approve each candidate before it is connected, with provenance details (source path and content hash) shown for transparency. The change also introduces dedicated modules for handling HTTP-based transports (SSE and Streamable HTTP) with strict bounds on response bodies to prevent OOM attacks, and adds robust OAuth2 support for MCP servers requiring authentication. Additionally, the system now enforces safe custom headers for MCP HTTP requests, rejecting empty, reserved, or control-character-containing headers to prevent header injection or protocol breakage.
crates/tui/src/mcp · high confidence
Introduce core runtime library with job and thread management
The \crates/core/src/lib.rs\ file was added, establishing the central runtime library for the application. This module defines the core data structures and logic for managing background jobs (including status tracking, retry metadata, and history) and thread operations (including initial history states and thread metadata). It integrates with the configuration, execution policy, state, and protocol crates to provide the foundational services for the headless runtime.
crates/core/src · high confidence
Introduce durable fleet management, alerting, and capability badges
The TUI now includes a complete, durable fleet management system. A new \FleetManager\ coordinates workers via a JSONL ledger, while \FleetExecutor\ and \FleetHost\ enable running workers as real subprocesses. Users can now manage fleets via CLI and TUI, view status and artifacts, and configure alerts for worker states. Additionally, capability badges (e.g., context window, tool support) are displayed for fleet routes, and the system enforces strict route preflighting and authority envelopes for workers.
crates/tui/src/fleet · high confidence
Introduce embedded local web client for the TUI
The TUI now ships with an embedded local web client (app.mjs, styles.css, index.html) that provides a browser-based interface to the local runtime. Users can view live thread and item state, manage approvals and user inputs, and send replies or resolve tool calls through a dedicated dashboard UI. The client enforces fail-closed target resolution, ensuring that replies and approvals are only sent to live, active threads, and it maintains event continuity to prevent gaps in the live stream.
_crates/tui/src/runtime\web · high confidence
Introduce exact base-prompt preview and consolidate prompt text sources
The TUI now provides an exact, byte-level preview of the effective base prompt, showing each segment's origin, size, and digest so users can verify what will be sent to the model. This new \base\_preview\ module replaces the previous preview mechanism with a stricter, provenance-tracked approach. Additionally, all bundled prompt text constants (constitution, language law, output formatting, personality, and mode deltas) have been consolidated from multiple files into a single \text.rs\ module, ensuring the prompt contract is maintained in one place without changing the actual prompt content.
crates/tui/src/prompts · high confidence
Introduce explicit tool execution outcomes and resource-based parallel scheduling
The tools crate now exposes a structured \ToolExecutionOutcome\ that maps legacy \ToolResult\ and \ToolError\ states to explicit terminal statuses (Succeeded, Failed, Denied, InvalidArguments, Cancelled, TimedOut). This allows the runtime to distinguish between different failure modes rather than treating all errors as generic failures. Additionally, a new \ResourceClaim\ system enables the scheduler to batch non-conflicting tool calls for parallel execution, ensuring that writes to the same path or global-exclusive resources are serialized while safe reads and unrelated writes can run concurrently.
crates/tools · high confidence
Introduce long-lived Python REPL runtime for agent loops
Added a new \repl\ module in the TUI crate that provides a long-lived Python runtime for executing code blocks within the agent loop. The \runtime.rs\ file implements a persistent Python subprocess that communicates via stdin/stdout pipes using a custom RPC protocol, replacing the previous HTTP sidecar approach. The \sandbox.rs\ file adds utilities to detect and extract \\ \\\repl \\` fenced code blocks from agent responses. This enables the model to execute Python code inline during conversation, with state and imports persisting across rounds.
crates/tui/src/repl · high confidence
Introduce new tool implementation files for the TUI tools module
Added new source files for the TUI tools module: \apply\_patch.rs\ implements the \apply\_patch\ tool for unified diff patching with fuzzy matching and CRLF preservation; \approval\_cache.rs\ provides fingerprint-based caching for tool approvals, distinguishing between exact denial keys and lossy approval grouping keys; \arg\repair.rs\ implements a deterministic JSON argument repair ladder to handle malformed tool-call inputs; \automation.rs\ consolidates the legacy \automation\\*\ execution aliases into a single \automation\ tool with an \action\ parameter routing to per-action logic.
crates/tui/src/tools · high confidence
Introduce pluggable sandbox backend architecture with Alibaba OpenSandbox adapter
The sandbox module now supports an external, remote execution backend via a new \SandboxBackend\ trait and an \OpenSandboxBackend\ adapter. When configured, shell commands are routed to a remote service instead of being executed locally. The system also introduces a \CommandSpec\ struct to encapsulate all command execution details, and adds process hardening for Linux via \prctl\ and \setrlimit\ calls. Additionally, the module is reorganized into \crates/tui/src/sandbox/\, and the \policy.rs\ file is moved and updated to support the new architecture.
crates/tui/src/sandbox · high confidence
Introduce plugin install module with strict security and validation rules
The \crates/tui/src/plugins/install\ module has been introduced to handle plugin installation, mirroring the existing skill installer's pipeline seams. It enforces strict security rules: all bundles are staged in a private \.staging-\*\ directory before being atomically renamed into place, ensuring no partial installs appear on disk. The module validates that a bundle contains exactly one \plugin.toml\ or \plugin.json\ manifest, rejects path traversal and symlinks, and caps bundle size. It reuses shared machinery for fetching, network gating, and marker writing from the skill installer, but adapts the scan/extract step for plugin-shaped bundles. The \place\ module ensures the final path is a direct child of the plugins directory, while the \stage\ module handles local copies and tarball extraction with strict containment checks.
crates/tui/src/plugins/install · high confidence
Introduce shared bridge-core helpers and ThreadStore
A new shared library (integrations/bridge-core/src/lib.mjs) is introduced, providing core utilities for the bridge integration. This includes a ThreadStore class for managing chat state, message deduplication, and action tokens, along with helper functions for parsing environment variables, commands, and text content. Tests are added to verify the behavior of these new components.
integrations/bridge-core · high confidence
Introduce structured hook event system for external integrations
A new hook system has been added to the runtime, providing a structured way to emit lifecycle events such as response starts, deltas, tool invocations, and job states. The implementation includes a \HookEvent\ enum that serializes to JSON, along with sink implementations for writing to stdout, appending to JSONL files with thread-safe locking, and posting to HTTP endpoints. This enables users to capture and process detailed runtime events for debugging, logging, or external monitoring.
crates/hooks · high confidence
Introduce the Codewhale public site and community assistant automation
The web directory now contains the full source for the codewhale.net public site, built on Next.js 15 with Tailwind CSS and deployed to Cloudflare Workers. The site provides a documentation portal with bilingual (English and Chinese) content, including a home page, install instructions, and a community feed. Additionally, a community assistant agent is introduced, consisting of Cloudflare Cron Triggers that use the DeepSeek API to draft triage comments, PR reviews, stale issue nudges, and weekly digests. These drafts are stored in Workers KV and presented in an admin panel for maintainer review, ensuring no automated posts to GitHub without explicit approval. The site also includes a facts pipeline that derives version and provider counts from the repository, exposing a public \/api/facts\ endpoint for provenance verification.
web · high confidence
Introduce the Work Graph as the single authoritative work ledger for sessions
The TUI now uses a new \WorkGraph\ data structure to manage session work, replacing the previous flat Plan and To-do trackers. This graph tracks objectives, plan steps, operations, evidence, and approvals as a directed acyclic graph, allowing agents to mark work as done by assertion while maintaining dependency structure and distinct completion/verification states. The change includes a deterministic import of legacy Plan and To-do state, a pure reducer for all mutations, and pure projections for the legacy UI views, ensuring that the graph owns all state and never invents liveness data.
_crates/tui/src/work\graph · high confidence
Introduce the Workflow JS runtime for dynamic workflow execution
The \crates/workflow-js\ crate now provides the imperative, scriptable half of the Workflow system, executing model-authored JavaScript programs via a sandboxed QuickJS runtime. This change introduces the \WorkflowDriver\ trait and the \TaskRequest\/\TaskCompletion\ types that bridge the VM to the subagent engine, enabling features like cancellable VM runs, a host-only tool deny list, and schema-based response validation. A \FakeDriver\ test harness is also added to exercise the runtime without spawning real subagents.
crates/workflow-js/src · high confidence
Introduce the route foundation for EPIC \#2608
Added the core types and logic for the new route resolution system. This includes the \ReadyRouteCandidate\ and \RouteResolver\ to map model selectors to executable routes, along with supporting types for provider/model offerings, capabilities, and limit overrides. The resolver enforces strict provider scoping and handles the \auto\ sentinel. Tests verify that every provider kind has a well-formed descriptor and resolves a default route.
crates/config/src/route · high confidence
Introduce the unified GitHub tool with issue/PR context, commenting, and closing capabilities
The GitHub integration is now a single \github\ tool that routes to specific actions: \issue\_context\ and \pr\_context\ for reading issue and pull request details, \comment\ to post evidence-backed comments, and \close\_issue\/\close\_pr\ to close threads with structured acceptance evidence. The tool uses the \gh\ CLI, automatically locating it via environment variables or standard system paths, and handles large text payloads by spilling them into task artifacts. Read-only actions are available in Plan mode, while write actions require approval and evidence.
crates/tui/src/tools/github · high confidence
Introduces shared, locale-aware content modules for the getting-started path and product vocabulary
The web application now uses new shared modules in web/lib/content to define the canonical four-step getting-started path (install, first session, provider connection, and Fleet workflow) and a structured product vocabulary (Fleet, Workflow, Lane, Runtime, modes, postures, and route identity). These modules provide English and Chinese translations for all user-facing text, ensuring consistent copy across the homepage band and /docs/guide pages. A corresponding test suite validates that the content matches the public fact matrix, enforces complete English/Chinese pairs, and verifies that all internal links point to existing routes.
web/lib/content · high confidence
Introduces structured configuration for provider authentication, harness profiles, and model reference data
The config crate now includes new modules for managing provider authentication sources (supporting command-based or secret-based credential retrieval), harness profiles that define agent postures (Standard, CacheHeavy, Lean, Custom) with associated compaction and tool-surface policies, and a read-only model reference database that projects catalog offerings into factual cards (modality, context window, pricing). Additionally, the config document writer has been refactored to use a shared write lock for thread-safe, lossless TOML mutation, and the config parser now automatically heals deeply nested \extras\ tables to prevent loss of user state like trust records and tokens.
crates/config/src · high confidence
Layered permission rulesets and typed ask rules for shell commands
The execution policy engine now supports layered permission rulesets (builtin defaults, agent, and user) with a new typed \ToolAskRule\ that can explicitly \allow\, \deny\, or \ask\ for specific command prefixes. This change introduces a \bash\_arity\ dictionary to accurately match command prefixes against shell-wrapped or chained commands, ensuring that deny rules are correctly applied to the actual commands a shell would execute. The authorization order is now deterministic, with deny rules taking precedence over allow rules within the same layer, and higher-priority layers (like user rules) overriding lower ones.
crates/execpolicy · high confidence
Live telemetry ingestion endpoint at telemetry.codewhale.net
A new Cloudflare Worker has been deployed to handle telemetry data from Codewhare clients. The endpoint accepts POST requests at /v1/telemetry, writing batches to Workers Analytics Engine. The implementation enforces a strict privacy model: client IPs and geo-location data are never read, stored, or logged. The schema is closed, meaning any unexpected fields in the payload will be rejected. The service is live and configured to strip all IP-related headers and disable invocation logs to ensure no network address data is retained.
telemetry-ingest · high confidence
Localized homepage and layout for all supported locales
The web app now renders a fully localized homepage and layout for every supported locale. A new \web/app/\[locale\]/layout.tsx\ file provides the global shell (head, nav, footer, fonts, and structured data) for each locale, while \page.tsx\ renders the homepage content using locale-specific dictionaries. This change ensures that all visible strings, metadata, and UI components on the homepage are translated and culturally adapted for each language, replacing the previous English-only or fallback-based approach.
web/app/\[locale\] · high confidence
Manual trigger for community agent tasks
Added a new API endpoint at /api/cron that allows manual execution of community agent tasks (curate, triage, pr-review, stale, dupes, digest, facts-drift, linkcheck, and semantic-drift). The endpoint requires authentication via the x-cron-secret header and validates the requested task against a whitelist of supported operations.
web/app/api/cron · high confidence
Native API adapters for Anthropic Messages, OpenAI Responses, and provider-native search
The TUI client now implements dedicated adapters for the Anthropic Messages API, the OpenAI Responses API, and provider-native web search, each with their own request-shaping, streaming, and error-handling logic. The Anthropic adapter serializes native Messages API requests, handles signed-thinking replay, and normalizes cache telemetry. The OpenAI Responses adapter builds requests for the Codex backend, supporting model-specific reasoning effort mapping and encrypted reasoning replay. A new provider-native search client routes web search queries to OpenAI, xAI, and Anthropic endpoints using their respective wire formats. A shared stream-entry seam consolidates HTTP/1.1 fallback, idle timeouts, and header-wait policies across all streaming adapters. Additionally, a prepared-outbound-request seam provides a truthful manifest of the exact wire body, dialect, and route shape for each request.
crates/tui/src/client · high confidence
New /config, /permissions, /status, and /mode commands for TUI configuration
The TUI now provides a unified command-line interface for managing settings, permissions, and runtime state. Users can open the interactive config editor with /config, manage permission rules with /permissions, view a detailed runtime status report with /status, and switch operational modes with /mode. The /config command also supports setting individual values, applying bundled presets (e.g., /config preset calm), and auditing editability. The /permissions command allows listing and removing rules, while /status displays a comprehensive report of the current session, including provider, model, mode, safety policy, context usage, and token counts.
crates/tui/src/commands/groups/config · high confidence
New /goal, /init, /lsp, and /share commands
The TUI now supports four new project-level commands. /goal manages persistent, cross-turn goals with states (active, paused, blocked, complete) and a context-aware bare invocation that synthesizes an objective from the conversation. /init generates or updates an AGENTS.md project guide by gathering workspace context (Cargo.toml, package.json, git, CI/CD, build systems, test frameworks, and directory tree) and delegating content generation to the LLM agent. /lsp enables or disables LSP integration. /share exports the current session as a static HTML page and uploads it to a GitHub Gist using the gh CLI.
crates/tui/src/commands/groups/project · high confidence
New /memory and /note slash commands for persistent memory and notes
Users can now manage persistent memory and workspace notes directly from the TUI. The /memory command lets users view, clear, and edit the user memory file, and includes a /memory native subcommand for managing a local-native Markdown and FTS5 store (status, path, search, remember, import, get, export, reindex, delete). The /note command allows users to add, list, show, edit, remove, and clear persistent workspace notes stored in .codewale/notes.md (or .deepseek/notes.md). These commands provide a structured way to interact with and retrieve stored information without leaving the terminal.
crates/tui/src/commands/groups/memory · high confidence
New /restore, /review, and /skills commands for workspace management and skill discovery
Users can now use /restore to list and revert to previous workspace snapshots, /review to activate a code-review skill and send a target, and /skills to list, sync, inspect, or suggest skills from the local directory or remote registry. The /restore command requires trusted or full access to perform a restore, while /review and /skills provide new ways to interact with and manage skills.
crates/tui/src/commands/groups/skills · high confidence
New Activity Feed Page for GitHub Updates
A new Activity feed page has been added at /feed, displaying a live mirror of issues, pull requests, and releases from the Hmbown/CodeWhale GitHub repository. The page fetches and displays these updates every ten minutes, with separate sections for pull requests and issues, and includes direct links to open new issues, pull requests, and discussions on GitHub.
web/app/\[locale\]/feed · high confidence
New CI preflight and drift-gate scripts for web build and deploy
The web/scripts directory now includes several new Node.js scripts that enforce build and deployment correctness. check-cloudflare-deploy-env.mjs validates that Cloudflare account and token environment variables are present and valid before a Cloudflare deploy job runs. check-docs.mjs verifies that documentation topics point to existing source files, that the website version matches the workspace, and that install snippets and source checkout commands are up to date. check-facts.mjs compares the committed facts.generated.ts against a fresh derivation to catch provider-inventory drift and missing fields. check-kv-id.mjs ensures wrangler.jsonc contains real KV namespace IDs rather than placeholders. check-locales.mjs enforces that all locale dictionaries match the English reference keys and template tokens. compare-deployed-facts.mjs compares the deployed site's facts receipt against the current source revision. derive-facts.mjs generates the typed facts module from the workspace. These scripts collectively add automated checks for deployment configuration, documentation integrity, facts consistency, and locale parity.
web/scripts · high confidence
New Fleet management surfaces: roster, list, detail, and setup wizard
The TUI now includes four new views for managing saved FLEET configurations: a roster view (/fleet) that displays the operator and team members with capability badges; a list view (/fleet fleets) to select, rename, or delete saved fleets; a detail view for editing individual fleet configurations; and a setup wizard (/fleet setup) to configure roles, providers, and thinking budgets. These views are backed by the new fleet store and profile system, allowing users to define agent teams with specific roles (manager, scout, builder, reviewer, etc.) and persist them as named configurations.
crates/tui/src/tui/views · high confidence
New Runtime & Integrations page on the public site
A new 'Runtime & Integrations' page has been added to the public site, providing an overview of Codewhale's local Runtime API, HTTP/SSE, ACP stdio adapter, MCP servers, VS Code extension, and various messaging bridges (Telegram, Feishu/Lark, Weixin). The page details the trust boundaries, such as local-first operation, required authentication, and open protocols, and links to deeper documentation for each integration surface.
web/app/\[locale\]/runtime · high confidence
New TUI widgets: agent cards, decision cards, and keybinding hints
The TUI now renders in-transcript cards for sub-agent activity, including a \DelegateCard\ that shows the status, summary, and recent actions of a single agent invocation, and a \FanoutCard\ for multi-agent fanouts. A new \DecisionCard\ widget provides structured user input with numbered options and keyboard navigation. Additionally, a \KeyBinding\ helper renders platform-specific key hints (e.g., \⌥+\ on macOS, \alt+\ elsewhere) for shortcuts and help overlays. These widgets are wired into the chat transcript and header, replacing older header and footer rendering paths.
crates/tui/src/tui/widgets · high confidence
New admin interface for community assistant drafts
A new admin page at /admin provides a maintainer-only interface for reviewing, editing, posting, or discarding community assistant drafts. The page displays pending and posted drafts with their type labels and target numbers, allowing maintainers to approve or remove content generated by the community agent. Authentication is required via a MAINTAINER\_TOKEN environment variable, and the interface supports both English and Chinese locales.
web/app/\[locale\]/admin · high confidence
New automated community-maintenance and site-health checks
The web library now includes a suite of automated maintenance tools: a community agent that generates draft comments for GitHub issues and pull requests, a daily link checker that flags broken external URLs, and a semantic drift detector that compares site copy against recent changes. These tools write structured drafts to a shared key-value store, which the existing /admin interface can then review and publish. The suite is accompanied by comprehensive unit tests for the agent logic, form parsing, and fact-checking helpers.
web/lib · high confidence
New community hub page for open-source contributions
A new community page has been added at /community, providing a centralized hub for users to engage with the project. The page outlines four primary ways to contribute: reporting issues, improving code or tests, enhancing documentation or translations, and reviewing existing work. It also links to the repository activity feed, community digest, and public roadmap, while crediting contributors in the release notes.
web/app/\[locale\]/community · high confidence
New core slash commands and acceptance tests
The TUI now exposes a suite of new slash commands for managing the application's core state and configuration. Users can now use /advisor to toggle the background advisor watcher, /agent to launch and control sub-agents, /anchor to pin critical facts across compaction cycles, /clear to reset the conversation, /constitution to manage user-global collaboration rules, /effort (or /thinking) to adjust the model's reasoning depth, /exit to quit, /feedback to submit reports, /fleet to manage worker orchestration, /help for documentation, /hf for Hugging Face MCP setup, and /modeldb to browse the model reference database. Additionally, acceptance tests have been added to verify the visible output of these core commands.
crates/tui/src/commands/groups/core · high confidence
New debug commands for token, cost, cache, and changelog inspection
The TUI now includes a suite of debug commands under the \/debug\ group, providing deeper visibility into session state. The \/tokens\ and \/cost\ commands report token usage, cache hit/miss statistics, and session cost estimates with explicit coverage and exclusion notes. The \/cache\ command exposes per-turn prefix-cache telemetry, warmup status, and inspection of the prepared outbound request manifest. The \/change\ command displays the embedded Codewhale changelog, with automatic translation of the latest version section into the user's locale. Additionally, \/preview-request\ (alias \/dryrun\) allows an offline, redacted preview of the next outbound request, and \/undo\ attempts to revert workspace files via snapshot rollback before falling back to conversation undo.
crates/tui/src/commands/groups/debug · high confidence
New first-run onboarding flow with language, appearance, and mental models screens
First-time users now see a structured onboarding sequence that guides them through choosing a language, selecting an appearance theme, and understanding the application's modes and permissions. The welcome screen outlines the setup steps, the language picker offers all supported locales plus an auto-detect option, and the mental models screen explains the Plan, Act, and Operate modes along with permission levels. This replaces the previous direct entry into the main interface, ensuring new users are oriented to the tool's structure and capabilities before starting.
crates/tui/src/tui/onboarding · high confidence
New guided constitution and fleet setup wizard in the TUI
The TUI setup flow now includes a guided constitution-first wizard that lets users draft and ratify their user constitution, and configure fleet agent profiles, before proceeding to provider, runtime, and tools/MCP setup steps. The wizard presents read-only readiness cards for each step, shows a model-drafted constitution and fleet profile preview for ratification, and persists state across the setup sequence.
crates/tui/src/tui/setup · high confidence
New localized web components for documentation, navigation, and installation
The web components directory has been refactored to support full localization (i18n) across English and Chinese. New or updated components include a bilingual docs search and sidebar, a FAQ search, a mobile menu, a locale switcher, and a theme toggle. The navigation bar now uses dictionary-driven labels for the masthead, star badge, and links. The footer, install binary selector, and getting-started steps also support Chinese text. These changes enable the public site to display content in multiple languages without code branches, improving accessibility and user experience for non-English speakers.
web/components · high confidence
New npm wrapper scripts for CodeWhale installation and runtime
The npm package now includes new JavaScript scripts (artifacts.js, install.js, run.js, verify-release-assets.js) that handle downloading and verifying prebuilt binaries for Linux, macOS, Windows, and Android. The install script enforces Node.js 18+, supports a CNB mirror for China-friendly downloads, and validates glibc compatibility on Linux. The run script launches the appropriate binary, and the verify script ensures all release assets are accessible. These scripts replace previous installation mechanisms and align the npm wrapper with the new CodeWhale branding.
npm/codewhale/scripts · high confidence
New protocol types for agent runs, fleet runs, and workrooms
The protocol crate now exposes new serializable data models for tracking agent runs, fleet operations, and workroom conversations. \AgentRunSnapshot\ provides a dependency-neutral, uniform read model for any unit of agent work, carrying scalar budget and lifecycle state without exposing internal subsystem types. \FleetRun\ and related types define the durable control-plane contract for fleet runs, including task specs, worker specs, and runtime events. \Workroom\ types introduce durable chat-native containers for threaded agent work, supporting GitHub references and event attribution. These additions enable consistent, cross-system visibility into agent execution and fleet management.
crates/protocol/src · high confidence
New release validation and hygiene scripts
Added new scripts in the release pipeline to improve release safety and automation. app-server-smoke.sh and its test validate the app-server runtime API and provider/model matrix. assemble-release-assets.js and its test ensure release assets are assembled and verified correctly, including checksums and Windows launchers. branch-hygiene.sh and its test manage branch cleanup after merges. check-ohos-deps.sh validates the OpenHarmony dependency graph. check-published.sh verifies that release versions are correctly published on npm and crates.io. check-versions.sh enforces version consistency across the workspace, npm, and Cargo.lock.
scripts/release · high confidence
New roadmap page with live-updating status and detailed telemetry transparency
A new /roadmap page has been added to the public site, displaying a structured list of shipped, underway, considered, and ruled-out features in both English and Chinese. The page dynamically fetches live updates from GitHub issues and releases, falling back to static content if the feed is unavailable. It also provides extensive transparency regarding the product's telemetry practices, detailing what is collected, how to disable it, and the specific data points that are never collected.
web/app/\[locale\]/roadmap · high confidence
New scripts for enforcing one-way ceilings and validating structural invariants
Added a suite of new scripts in the \scripts/\ directory to enforce one-way ceilings and validate structural invariants across the repository. These include \check-dead-code-budget.py\ to prevent the \\#\[allow(dead\_code)\]\ attribute count from growing, \check-persistence-backlog-budget.py\ to monitor paused persistence backlog metrics, \check-runtime-contract-budget.py\ to enforce ceilings on the provider-free runtime contract, and \check-source-structure-budget.py\ to limit the growth of Rust source files and modules. Additionally, new scripts validate that the provider registry matches the shipped configuration (\check-provider-registry.py\), that co-author trailers are mappable (\check-coauthor-trailers.py\), and that localized READMEs remain in sync with the English version (\check-readme-translations.py\, \check-readme-locales.sh\). A new \catalog\_models\_dev.py\ script automates the refresh and snapshot of the Models.dev catalog, while \catalog\_models\_dev\_test.py\ provides offline tests for it.
scripts · high confidence
New scripts to record and validate media assets for v0.9.2
Added \scripts/media/record-session.sh\ and \scripts/media/check-media-assets.py\ to automate the capture and verification of the v0.9.2 real session media. The shell script records the session in a sealed environment, ensuring no credentials are captured, while the Python script validates the resulting assets against the budgets defined in \web/lib/media-manifest.ts\. This replaces manual checks with an automated pipeline that verifies file sizes, dimensions, and durations before publication.
scripts/media · high confidence
New session management slash commands
The TUI now exposes a suite of slash commands for session management: /save, /load, /new, /rename, /purge, /fork, /export, /relay, /rc, /sessions, /compact, and /structcopy. These commands allow users to save and load sessions, create new ones, rename them, fork conversations, export transcripts or structured data, relay session state, control remote sessions, manage the sessions list, compact context, and copy structured data to the clipboard. An acceptance test suite for these workflows has also been added.
crates/tui/src/commands/groups/session · high confidence
New shared settings-picker framework for consistent navigation and layout
The TUI now includes a shared settings-picker framework that provides a consistent user experience across all settings dialogs. This new component standardizes keyboard navigation (including search, tab switching, and row selection), applies responsive layout logic (side-by-side or stacked views), and manages the preview/commit lifecycle. Users will experience smoother, more predictable interactions when browsing and selecting settings options.
_crates/tui/src/tui/settings\picker · high confidence
New skills manager and audit infrastructure
The skills subsystem has been refactored to introduce a bounded, read-only audit inventory that separates what is on disk from the runtime SkillRegistry. This new audit module, along with dedicated modules for installation, mutation control, and package digesting, provides a stable foundation for a unified skills manager view. Users will see a consolidated interface for managing, installing, and auditing skills, with improved security guarantees such as path-traversal and symlink escape prevention during installation.
crates/tui/src/skills · high confidence
New state management crate for threads, messages, and jobs
The \crates/state/src/lib.rs\ file introduces a new \StateStore\ module that manages persistent state for conversation threads, messages, and background jobs. It defines data structures for thread metadata, message records with parent-child relationships for branching conversations, checkpoints, and job states. This provides the foundational storage layer for conversation history and task tracking.
crates/state/src · high confidence
New utility slash commands for attachments, automations, jobs, MCP, network policy, and tasks
The TUI now exposes a suite of new slash commands in the utility group: /attach for managing image and video attachments with size and format validation; /automation for listing, showing, pausing, resuming, deleting, and running scheduled automations; /jobs for managing shell jobs (list, show, poll, wait, stdin, cancel); /mcp for managing Model Context Protocol servers (init, add, enable, disable, remove, login, import, validate, reload); /network for managing the host allow/deny list and default policy; and /task for adding, listing, digesting, showing, and canceling tasks. These commands are registered in crates/tui/src/commands/groups/utility/mod.rs and implement their respective behaviors via AppAction variants.
crates/tui/src/commands/groups/utility · high confidence
New workflow recipes for release acceptance and operate scenarios
Added new workflow definitions in the workflows directory: a declarative JavaScript example for auditing issue fixes with parallel specialists, a best-of-n candidate search recipe for the operate mode, a parallel scout recipe with partial-failure synthesis, a read-only audit starter, a staged bugfix starter, and a comprehensive stopship release acceptance fixture that validates the Fleet, Workflow, Lane, and Runtime contract through a five-role gate chain.
workflows · high confidence
Post-edit LSP diagnostics injection for supported languages
The TUI now automatically runs the appropriate LSP server after a successful file edit to fetch and inject diagnostics (errors, warnings, hints) into the model context. This feature supports Rust, Go, Python, TypeScript, JavaScript, Java, PHP, Vue, C, and C++. Users can enable or disable the feature, configure timeouts, set diagnostic limits, and override or add custom language servers via the \\[lsp\]\ section in \\~/.deepseek/config.toml\. The system handles missing binaries or timeouts gracefully by skipping diagnostics rather than stalling the agent.
crates/tui/src/lsp · high confidence
Runtime API gains session management, workspace status, and embedded web client
The TUI's runtime API now exposes new endpoints for managing saved sessions (listing, patching, saving, and summarizing), reporting workspace git status, and serving an embedded web client. Authentication is handled via a generated or provided bearer token, with additional cookie-based validation for the web client to ensure same-origin requests.
_crates/tui/src/runtime\api · high confidence
Stream display clock and buffer implementation
The streaming module now includes a \StreamDisplayClock\ that controls how often provider deltas are committed to the visible transcript. By default, it runs at \~60 FPS (16ms intervals), coalescing incoming deltas into single history mutations per beat. The \StreamBuffer\ holds pending deltas between beats. A catch-up mechanism is staged to accelerate the clock when backlog exceeds 160 items or the oldest item is over 1.2 seconds old, though the catch-up logic is currently staged and not yet active. This ensures smooth, consistent rendering of streaming text without stuttering from rapid, small updates.
crates/tui/src/tui/streaming · high confidence
TUI changelog and build scaffolding for v0.9.4
The crates/tui directory now includes a generated CHANGELOG.md that documents the v0.9.4 release, including new features like memory maintenance, sub-agent checkpoint resume, MCP registry discovery, and opt-in product telemetry. The directory also contains an AGENTS.md file providing guidance on the TUI's shell grammar, localization, and verification steps. Additionally, build.rs files for both cli and tui crates were added to handle build versioning and Windows stack configuration.
crates/tui · high confidence
TUI theme system overhaul: custom background colors and palette migration
The TUI now supports custom background colors for UI elements, allowing users to tailor the visual appearance of the interface beyond the default palettes. Additionally, the system has been migrated to use \Color::Reset\ for consistent color handling across all UI widgets, ensuring that theme toggles and state resets behave predictably. This change also includes the introduction of a \/theme\ command to toggle between dark and light modes, alongside the addition of several new built-in themes (Catppuccin, Tokyo Night, Dracula, and Gruvbox) and a theme picker for easier selection.
crates/tui/src · high confidence
Unified command dispatch with user-command precedence
The TUI now uses a centralized command registry that enforces user-defined command precedence over built-in commands. User commands (from \\~/.codewhale/commands/\ and workspace-local directories) are loaded into a dedicated registry and dispatched before the built-in command registry, allowing users to shadow or override built-in commands. The system also supports saved workflows as slash commands and provides acceptance tests for dispatch precedence and error semantics.
crates/tui/src/commands · high confidence
Unified web search and fetch pipeline with shared SSRF guard and citation registry
The web tool suite now uses a shared, unified pipeline for fetching and searching the web, introducing a new \backend.rs\ module that defines a \SearchBackend\ trait and a \SearchBackendChain\ that sequences provider-native and configured search backends (Bing, DuckDuckGo, Tavily, Bocha, Metaso, Searxng, Baidu, Volcengine, Sofya). A new \guard.rs\ module provides a shared SSRF guard that validates URLs, enforces network policy, resolves DNS, and returns a DNS pin to prevent TOCTOU rebinding. A new \cache.rs\ module provides session-scoped TTL caches for search and fetch results. A new \citations.rs\ module provides a session-scoped registry for web citations, enabling evidence-based attribution. The \extract.rs\ module handles content-type routing and document extraction (HTML, Markdown, PDF, media) with a bounded character budget for inline output, spilling over to session artifacts when content is too large. The \scrape.rs\ module provides shared scrapers for DuckDuckGo and Bing with a spam filter. These changes standardize behavior across \fetch\_url\, \web\_search\, and \web.run\, ensuring consistent security, caching, and citation tracking.
crates/tui/src/tools/web · high confidence
Unified work-surface rail with resizable panels and persistent sizing
The work surface (the top bar/rail) has been refactored into a unified component that supports four placement options (Top, Left, Right, Off) and four panel types (Tasks, Agents, Context, Pinned). Users can now resize the work surface via mouse drag or keyboard, with the dimensions (top\_height, side\_width) persisting in settings. The rail also consolidates the legacy sidebar panels, allowing users to switch between different views of their work and sub-agents, with each row remaining selectable and clickable.
_crates/tui/src/tui/work\surface · high confidence
Workflow plan elevation assessment and exact Fleet schema
The workflow crate introduces a new \elevation.rs\ module that performs pure, headless analysis of a Workflow plan to determine if an operator approval card is required, exposing fields like writes, shell, network, and budget in the approval card. Additionally, the crate adds \fleet\_exact.rs\ for a fully resolved, immutable Fleet schema that rejects late-binding selectors, \fleet\_preflight.rs\ to freeze provider/model routes before execution, \fleet\_reasoning.rs\ to resolve reasoning tiers and produce durable receipts, \fleet\_composition.rs\ for a setup-time model pool suggestion schema, \fleet\_snapshot.rs\ to capture an immutable, secret-free snapshot of the Fleet at workflow start, and \gates.rs\ to define workflow gate nodes and lane-scoped handoffs.
crates/workflow · high confidence
Workspace snapshot safety net for turn rollback
The TUI now creates per-workspace side-git repositories under the state directory (defaulting to \~/.codewhale/snapshots) to record pre- and post-turn snapshots. This enables users to roll back a turn using the /restore command or by asking the model to undo the last edit. The feature includes automatic pruning of old snapshots (default 7-day retention) and size-based self-disabling for large workspaces to prevent performance issues.
crates/tui/src/snapshot · high confidence
Removals
Removal of legacy CLI command modules
The \src/commands\ directory has been refactored by removing the \config\, \core\, \debug\, \init\, \queue\, \rlm\, \session\, and \skills\ modules. This eliminates the previous slash-command interface for managing configuration, session state, debugging, and external memory (RLM/Aleph) from the terminal user interface.
src/commands · high confidence
Removal of legacy DeepSeek client and related modules
The \src/client.rs\ file, which implemented the \DeepSeekClient\ for the DeepSeek OpenAI-compatible APIs, has been removed. Additionally, several other modules have been deleted from the \src\ directory, including \command\_safety.rs\ (shell command safety analysis), \compaction.rs\ (context compaction logic), \config.rs\ (configuration loading), \duo.rs\ (autocoding state machine), \hooks.rs\ (lifecycle hooks), \logging.rs\ (verbose logging helpers), \main.rs\ (CLI entry point), \mcp.rs\ (Model Context Protocol implementation), \models.rs\ (API request/response structures), and the \modules\ directory containing text chat workflows. These deletions indicate a significant restructuring or removal of the application's core functionality, including the primary API client, configuration management, and various feature modules.
src · high confidence
Removal of legacy core engine architecture
The legacy core engine implementation has been removed from the codebase. This includes the deletion of the main engine module (engine.rs) and its associated support files for operations (ops.rs), events (events.rs), session state (session.rs), and turn context (turn.rs). This change eliminates the previous internal API and event-driven communication layer between the UI and the AI processing logic.
src/core · high confidence
Removal of the responses\_api\_proxy component
The \responses\_api\_proxy\ module, which provided a minimal HTTP proxy for forwarding requests to the DeepSeek API, has been removed from the codebase. This change eliminates the local proxying capability, meaning users can no longer run this specific proxy service.
_src/responses\_api\proxy · high confidence
Removed execpolicy and sandbox modules
The execpolicy module (including amend, decision, error, execpolicycheck, parser, policy, and rule) and the sandbox module (including landlock and seatbelt implementations) have been deleted from the codebase. This removes the ability to evaluate commands against policy files and to execute commands within restricted environments on Linux (Landlock) and macOS (Seatbelt).
src/execpolicy, src/sandbox · high confidence
Removed legacy TUI implementation
The entire \src/tui\ module, including \app.rs\, \approval.rs\, \clipboard.rs\, \history.rs\, \mod.rs\, \scrolling.rs\, \streaming.rs\, \transcript.rs\, and \ui.rs\, has been deleted. This removes the previous terminal user interface implementation from the codebase.
src/tui · high confidence
Architecture
Config module refactored into dedicated leaf modules
The TUI configuration module has been reorganized to improve code structure and testability. The monolithic \config.rs\ file has been split into separate, self-contained modules for models, paths, search providers, sub-agent limits, and tests. This refactoring ensures that configuration constants and path resolution helpers are isolated, making the codebase easier to maintain and allowing integration tests to include specific modules without pulling in unrelated crate dependencies. Existing configuration loading behavior remains unchanged, as the new modules are re-exported to maintain backward compatibility.
crates/tui/src/config · high confidence
Engine core modularized into separate modules
The engine core has been refactored into separate modules for approval, context budgeting, tool dispatch, handle, and LSP hooks. This modularization improves code organization and maintainability without changing user-facing behavior.
crates/tui/src/core/engine · high confidence
Refactor TUI UI module into focused, testable components
The large \ui.rs\ file has been split into several smaller, dedicated modules: \activity\_detail.rs\ (reasoning detail and turn inspector), \apply.rs\ (state application logic), \dispatch.rs\ (message dispatch and queuing), and \event\_loop.rs\ (the main TUI event loop). This refactoring improves code organization and maintainability without changing user-facing behavior.
crates/tui/src/tui/ui · high confidence
Refactor hooks into config and executor modules
The hooks implementation in crates/tui/src/hooks has been split into two new files: config.rs, which defines the HookEvent enum, HookSteering enum, and HookCondition struct, and executor.rs, which contains the HookContext struct and the logic for executing hooks. This refactoring separates the configuration and event definitions from the execution logic, improving code organization and maintainability.
crates/tui/src/hooks · high confidence
Restructured history transcript rendering into dedicated modules
The history rendering logic has been refactored into separate, dedicated modules for each transcript cell type, improving code organization and maintainability. New files include agent\_activity.rs for agent and activity metadata, archived\_context.rs for parsing and rendering archived context blocks, checklist.rs for checklist and todo updates, constants.rs for shared rendering constants, file\_mutation.rs for structured file change receipts, latex\_render.rs for math expression rendering, message.rs for user and assistant messages, plan.rs for plan updates, and thinking.rs for reasoning/thinking cells. This modular structure allows each cell type to have its own focused rendering logic while sharing common utilities and constants.
crates/tui/src/tui/history · high confidence
TUI app logic extracted into dedicated modules
The \App\ struct's implementation has been refactored into separate files (\composer.rs\, \init.rs\, \status.rs\, \types.rs\, and \tests.rs\) to improve code organization and maintainability. This change moves composer state and behavior, application initialization, status/toast management, and plain data types into their respective modules, while keeping the central \app.rs\ focused on state and behavior. The public API remains unchanged as items are re-exported from \app.rs\.
crates/tui/src/tui/app · high confidence
Behavioural changes
Add full localization for the website chrome and home page in 10 languages
The website's navigation, footer, theme switcher, live ticker, and the entire home page copy are now fully translated into English, Spanish, Indonesian, Japanese, Korean, Portuguese (Brazilian), Russian, Ukrainian, Vietnamese, and Chinese. Each locale provides a complete set of translation keys for the shared chrome and the landing page, with a build-time check ensuring every non-English locale matches the English reference keys exactly. Untranslated locales fall back to English, and partial translations are marked with a '(partial)' badge in the language switcher.
web/lib/i18n/dictionaries · high confidence
Build system no longer triggers full rebuilds on local commits
The build process now decouples the version stamp from compilation, meaning local commits will no longer cause a full rebuild of the TUI and CLI. Additionally, the build script now emits a release-only build SHA for published binaries, while local builds display a (dev) marker instead of the local checkout's HEAD, preventing unnecessary rebuilds and ensuring consistent build times.
crates/build-support · medium confidence
Centralized authority and mode policy for the TUI
The TUI now enforces a single source of truth for permission posture, shell access, trust mode, and approval behavior per application mode. A new \authority\ module introduces \ModeSessionPrefs\ and \EffectiveModePolicy\ to map each mode (Plan, Agent, Operate, Yolo) to a consistent set of permissions. This ensures that the UI, the engine, and the model all see the same effective policy, preventing drift between the prompt metadata, tool catalogs, and runtime gates. The \TurnAuthority\ struct and \PolicyNarrowingEvent\ provide structured records of any runtime policy narrowing, ensuring that the UI status line, the \\<turn\_meta\>\ metadata line, and the doctor surface all report the same cause for any authority reduction.
crates/tui/src/core · high confidence
Doctor diagnostics run offline by default
The \codewhale-tui doctor\ command now defaults to an offline mode, meaning it will not check for updates, probe the API, or probe MCP by default. This change is accompanied by new tests in \crates/tui/src/doctor/tests.rs\ that verify the default probe request is fully offline, that CLI flags for live probes are incompatible with the \--json\ flag, and that the path report does not include secret file contents.
crates/tui/src/doctor · high confidence
Fix TUI rendering of wide and multi-byte characters
The TUI now correctly measures and renders wide characters (such as CJK, fullwidth, and emoji) and keycap glyphs, ensuring they occupy the correct number of columns. This prevents layout breakage, truncation, and visual artifacts caused by incorrect width calculations for multi-byte and wide glyphs.
crates/tui/src/tui · high confidence
Improved execpolicy command matching with heredoc and shell expansion support
The execpolicy matcher now normalizes commands by stripping heredoc bodies before pattern matching, ensuring that rules like \auto\_allow = \["cat \> file.txt"\]\ correctly match multi-line heredoc invocations. Additionally, deny rules are now evaluated against every command line the shell would actually run (including those wrapped in \sudo\, \bash -c\, or command substitutions), preventing evasion through shell metacharacters. Allow rules continue to match the command as written, preserving strict approval boundaries.
crates/tui/src/execpolicy · high confidence
Improved shell output handling and test coverage
Added output.rs to optimize shell output processing by reading only the delta or tail of the output buffer, avoiding full buffer clones for long-running processes. Added tests.rs with comprehensive tests for shell behavior, including exit status handling, workspace recovery, and Windows-specific shell tests.
crates/tui/src/tools/shell · high confidence
Improved text legibility with automatic contrast enforcement and terminal background detection
The TUI now detects the terminal's actual background color using the OSC 11 query and the COLORFGBG environment variable, rather than relying on a static dark-mode assumption. This enables the new contrast-enforcement layer to automatically lift foreground colors that fall below the WCAG AA readability floor (4.5:1 for body text, 3:1 for secondary chrome). As a result, community themes and user-authored overlays are now remapped to ensure all text remains legible against the detected surface, fixing issues where light-colored text appeared on light-colored backgrounds.
crates/tui/src/palette · medium confidence
Introduce runtime API types for capabilities, dynamic tools, and environment targeting
The runtime module now exposes structured types for the runtime API, including a capabilities map (account session, threads, turns, event replay, fleet operations, and environments) and experimental feature flags. It also defines the protocol for dynamic external tools, including their specifications, call parameters, and results, as well as environment targeting parameters for shell and filesystem work.
crates/protocol/src/runtime · medium confidence
Introduces secure account session storage and refines secret backend diagnostics
The \crates/secrets\ module now includes a new \account\ module that defines the data structures for storing and managing Codewhale account sessions, including \AccountAuthBundle\ for credentials and \RuntimeAccountInfo\ for status reporting. Additionally, the secret storage system has been updated to support a file-based fallback alongside the OS keyring, with a corrected reachability probe for the keyring backend and new diagnostic tests that verify the \diagnose\_secret\_backend\ function correctly reports backend status without exposing secret contents.
crates/secrets · medium confidence
MCP server integration now spawns real processes instead of using in-memory stubs
The \crates/mcp\ module has been refactored to replace the previous in-memory client stub with a real subprocess-based client (\ChildProcessMcpClient\). This ensures that configured MCP servers are actually spawned and their responses are handled correctly, rather than returning hardcoded or fake data. The change includes new types for server configuration (\McpServerConfig\, \ToolFilter\) and startup status tracking, along with test support for validating the new behavior.
crates/mcp · high confidence
New approval policy classification for tools
The TUI now classifies tool calls into specific risk and stakes categories (Safe, FileWrite, Shell, Network, McpRead, McpAction, Agent, Unknown) to determine the appropriate approval prompt. This allows the UI to render different levels of warning or routine confirmation based on the tool's potential impact, such as distinguishing between benign read-only operations and destructive state-changing actions.
crates/tui/src/tui/approval · medium confidence
Plugin management commands now support legacy executable tools alongside declarative bundles
The \/plugin\ command group now explicitly supports two distinct plugin models: declarative bundles (with install, update, and trust workflows) and legacy executable scripts (discovered from a configured directory). The \legacy\ module handles read-only listing and detail views for these scripts, while the \render\ module provides secure, escaped output for bundle details and review prompts. Users can now discover, list, and view details of legacy tools via \/plugin tools\, while bundle operations remain separate. Tests verify that read-only commands do not modify state and that trust operations require content and capability digests.
crates/tui/src/commands/groups/plugins · high confidence
Public site infrastructure and visual identity overhaul
The web application introduces a comprehensive visual redesign and infrastructure updates for the public-facing site. A new global CSS file establishes an 'ocean' color palette with specific light and dark mode tokens, alongside typography rules for CJK languages (Chinese, Japanese, Korean) to improve line-breaking and spacing. The site's branding is updated with a new SVG icon and a dynamic Open Graph image for social sharing. Additionally, the site's SEO is enhanced with a generated sitemap that includes multi-locale support for documentation and product pages, while robots.txt is configured to exclude admin and API routes.
web/app · high confidence
RLM loop now uses a persistent Python REPL over stdin/stdout instead of an HTTP sidecar
The Recursive Language Model (RLM) implementation has been refactored to replace the previous HTTP-based sidecar with a long-lived Python REPL process communicating via stdin/stdout pipes. This change introduces a new \bridge\ module that manages the RPC interface, tracks cumulative token usage and recursion depth, and enforces bounded context inspection through helper functions like \peek\, \search\, and \chunk\. The system prompt and turn loop have been updated to align with the reference implementation (Zhang et al., arXiv:2512.24601), ensuring that the root LLM only sees metadata and code rather than the full input body. This improves security by preventing large strings from appearing in process arguments and enhances performance by maintaining a persistent session state.
crates/tui/src/rlm · high confidence
Removal of Python CLI wrapper and version detection
The Python package's \\_\init\\_.py\ and \cli.py\ modules have been removed. This eliminates the automatic version detection from metadata or pyproject.toml, and removes the CLI entry point that previously downloaded and executed the DeepSeek binary. Users will no longer be able to invoke the CLI through this Python package.
python · medium confidence
Removal of TUI modal view infrastructure
The \src/tui/views/mod.rs\ file, which defined the \ModalView\ trait, \ViewStack\ container, and \HelpView\ implementation, has been deleted. This removes the internal framework for managing modal overlays and help screens within the terminal UI, indicating a structural change to how the application handles user interactions and display states.
src/tui/views · high confidence
Removal of npm package and CLI wrapper
The npm package has been removed from the project. The \npm/cli.js\ file, which previously acted as a Node.js wrapper to spawn the DeepSeek binary, and \npm/install.js\, which handled downloading the binary during installation, have been deleted. Users can no longer install or run the tool via npm; the project now relies solely on Cargo for building and distribution.
npm · high confidence
Removed custom header widget and restructured TUI widget module
The custom header bar widget (header.rs) was removed from the TUI widgets, and the widgets module (mod.rs) was significantly refactored. The ChatWidget was updated to manage its own scrollbar state and rendering logic, while the ComposerWidget's rendering implementation was adjusted. These changes streamline the UI component structure and remove the previous header rendering code.
src/tui/widgets · high confidence
Removed legacy toolset and core tooling infrastructure
Deleted the entire \src/tools\ directory, removing the legacy tooling system including the \ToolSpec\ trait, \ToolRegistry\, and all associated tool implementations such as \duo\, \file\, \patch\, \plan\, \rlm\, \search\, \shell\, and \subagent\. This removes the previous tool execution framework and its supporting infrastructure from the codebase.
src/tools · high confidence
Smarter update experience: throttled checks and package-manager-aware updates
The update system now respects user and environment preferences to avoid unnecessary network calls and to prevent breaking package-managed installs. Update checks are throttled to once per day (cached on disk) and suppressed in CI environments or when the user has opted out. For updates, the system detects whether the binary was installed via npm, Homebrew, or Cargo, and provides the correct command to update that installation rather than attempting a self-update that would break the package manager's state.
crates/release · high confidence
Updated unicode-width patch to version 0.2.2
The \unicode-width\ dependency patch has been updated to version 0.2.2. This update includes the latest Unicode data (version 17.0.0) and improves the handling of complex character sequences, such as emoji ZWJ sequences and script-specific ligatures, ensuring more accurate displayed width calculations for terminal UIs.
patches, patches/unicode-width-0.2.2 · high confidence
Windows installer preserves long user PATH values
The Windows installer now uses a PowerShell helper script to update the user's PATH environment variable via the Windows Registry API, ensuring that existing PATH entries longer than the previous 1024-character limit are preserved during installation and removal. This change prevents the installer from truncating or overwriting long PATH values, and includes a regression test to verify correct behavior with extended PATH strings.
scripts/installer · high confidence
Work surface rows become persistent, labeled, and clickable
The work surface now renders rows as persistent, labeled, and clickable objects across every panel, not just the task list. This change introduces a new layout module that calculates the height of the work surface strip based on the number of visible rows, ensuring the header (goal title and progress) and the scrollable list of agents/tasks are properly sized and aligned. The row rendering logic now supports different tiers of information (full, no tokens, no receipt, objective only) depending on available width, and each row includes hitboxes for interaction, allowing users to select, hover, and click on individual work items in the top strip and side rails.
_crates/tui/src/tui/work\surface/render · medium confidence
deepseek-tui package deprecated in favor of codewhale
The npm package deepseek-tui is now deprecated and serves only as a compatibility shim. Installing or running deepseek-tui now displays a console warning directing users to uninstall the old package and install codewhale instead. The package includes a deprecation notice script and updated documentation to guide the migration.
npm/deepseek-tui · high confidence
Fixes
Enforce absolute paths for Codewhale home and config overrides
The paths crate now validates environment variables (CODEWHALE\_HOME, CODEWHALE\_CONFIG\_PATH, DEEPSEEK\_CONFIG\_PATH) to ensure they are absolute paths. Relative paths or paths using the \\~\ tilde expansion that fail to resolve to an absolute path will now return an error. This prevents global configuration overrides from accidentally pointing to repository-relative files, ensuring that environment-provided paths are always treated as global and safe.
crates/paths · high confidence
Test coverage
Add comprehensive tests for cloud CLI commands and validation; Add end-to-end tests for the Workflow JS runtime; Added acceptance tests for core commands, session workflows, and tool lifecycle; Added comprehensive tests for runtime thread event handling; Added comprehensive tests for the File tool; Added integration tests for CLI dispatch, diagnostics, and telemetry; Added measurement tests for persistence backlog pressure; Added protocol parity tests for serialization and compatibility; Added test fixtures for TUI integration tests; Added tests for npm install, postinstall, and release asset verification; Added tests for state store schema and thread metadata operations; Added tests for system skill installation and validation; Added tests for the Models.dev-backed catalog cache; Added tests for the doctor command's offline mode and credential handling; Added tests for the new Fleet client functionality; Added tests for tool invocation and error handling; Added tests for tool specification and path resolution; Added unit tests for Feishu bridge utilities and startup ordering; Added unit tests for WeCom bridge approval and denial logic; Added unit tests for Weixin bridge core helpers; Expanded TUI test coverage for core workflows; Improved PDF tool error handling and test coverage; Improved error classification and test coverage for compaction failures; New PTY-based TUI integration test harness; Removed palette audit test suite.
Dependencies
Workspace migration: modular crates and rebranded dependencies
The project has been restructured into a modular Rust workspace with distinct crates for agent, app-server, CLI, config, core, execpolicy, hooks, lane, mcp, paths, protocol, release, secrets, state, telemetry, tools, TUI, workflow, and workflow-js, all under the 'codewhale' naming convention. The VS Code extension and Feishu bridge integrations have also been updated to reflect the new package names and dependencies.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 48.
Lenses
- Code Health 64
- Architecture 72
- Maturity 63
- Readiness 31
- Security 63
Changes since last survey
- 300 commits — 161 feature/other, 139 fixes
By area
- crates/tui — 173 commits
- (root) — 23 commits
- scripts/source-structure-budget.json — 13 commits
- docs/ops — 8 commits
- crates/cli — 7 commits
- web/app — 7 commits
- crates/config — 6 commits
- crates/telemetry — 6 commits
- web/components — 5 commits
- web/lib — 5 commits
- crates/execpolicy — 4 commits
- extensions/vscode — 3 commits
- crates/tools — 2 commits
- crates/workflow-js — 2 commits
- docs/CONFIGURATION.md — 2 commits
- docs/CONTRIBUTORS.md — 2 commits
- docs/TOOL_SURFACE.md — 2 commits
- docs/WINDOWS_BEGINNER.zh-CN.md — 2 commits
- docs/evidence — 2 commits
- docs/public-surface-facts.json — 2 commits
Notable commits
- fix: Merge FreeBSD build fix
- fix: Merge branch 'fix/windows-test-lane-0.9.4'
- fix: WIP fix(tui): clear the two standing clippy errors
- fix: chore(budgets): aggregate follows the bug-hunt fix stack (661724 -> 661794)
- fix: chore(budgets): aggregate follows the coordination-toast fix (+44 lines)
- fix: chore(budgets): aggregate follows the execpolicy security fixes (662061 -> 662167)
- fix: chore(budgets): aggregate follows the hooks/redaction/MCP-guard fixes
- fix: chore(budgets): aggregate follows the interact-stdin fix and snapshot test hardening
- fix: chore(budgets): aggregate follows the round-2 bug fixes (661843 -> 662015)
- fix: chore(budgets): aggregate follows the round-3 isolated fixes (662015 -> 662061)
- fix: chore(budgets): aggregate follows the truncator, refusal, and sandbox-honesty fixes
- fix: chore(gates): re-baseline source-structure aggregate for v0.9.4 ship fixes
- fix: docs(changelog): correct the Ratatui claim and record the 0.9.4 release-night fixes
- fix: docs(changelog): record the 2026-08-04 audit fixes for the 0.9.4 notes
- fix: docs: fix installer description and apply reviewer suggestions in Windows guide
- fix: fix(agent): a Fleet role is an identity, not a claim of write capability
- fix: fix(agent): fail closed when builder/worker is paired with read_only
- fix: fix(agent): only type=builder contradicts read_only, not type=worker
- fix: fix(audit): bump js-yaml in extensions/vscode ([GHSA redacted])
- fix: fix(ci): finish the Windows test-binary compile — gate the recorder's import too
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Hmbown/CodeWhale was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 7 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 21ed173cf121471ddf71a0caa46f35421f7d75e3 — the exact code this score is about.
- Scored under rubric-2026.08.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using localhost:5005/codehealth-analyzer rubric-2026.08.15.