These docs track main. Latest release: v1.0.0.

antigravity-booster
Project

Changelog

Release history, generated from CHANGELOG.md.

Notable changes to antigravity-booster. Versioning follows semver from 1.0.0 — see Stability.

The format follows Keep a Changelog. Entries before 0.4.0 were reconstructed from git history, so they summarise rather than enumerate.

Unreleased

[1.0.0] — 2026-10-08

booster is now a native Antigravity plugin. Install it with agy plugin install <git-url>, with no npm install step. Existing npm-global or checkout installs move over with agb migrate, and agb migrate --rollback reverses that. A unified PreToolUse policy guard now enforces frozen rails and the ADLC trust root inside every agy session. adlc ships vendored and digest-pinned, so the plugin is self-contained. This release was validated with a full migrate, doctor, live rail denial, rollback and re-migrate cycle on a real machine against agy 1.3.1.

Breaking: the legacy auto-approve-tests hook and the .agents/ tree are gone, agb doctor exits 1 (was 2) on failure, and bin.agb now points at dist/agb.mjs. See Removed and Changed below.

Added

  • Native Antigravity plugin layout (T-PLUGIN-01-CORE): agy plugin install <git-url> now stages a complete plugin with no npm install. Prebuilt bundles are committed under dist/ (agb.mjs, mcp-server.mjs, hooks/pre-tool-use.bundle.mjs) and contain only Node built-ins. Root commands/, agents/, hooks.json and mcp_config.json replace .agents/plugins/agb, which remains as a hookless agb-legacy-shim until the migration ticket.

  • Unified PreToolUse policy guard: frozen rails and the ADLC trust root (.adlc/config.json, the manifest, ticket shards, .git/) are denied in-session. Unlisted shell commands ask in repos with active rails. Booster never emits allow. It runs behind bin/hook-runner.sh, a fail-safe runner with a 9 s watchdog, and bin/node-launcher.sh, which finds a trusted Node >= 22.19 under a stripped GUI PATH.

  • agb bootstrap installs @adlc/antigravity from the vendored, integrity-pinned npm tarball and writes the ~/.local/bin/agb terminal shim. New --force-reinstall flag.

  • CI plugin-integrity job: bundle drift gate, shellcheck, and a byte-identity check of the vendored tarball against the npm release.

  • Vendored adlc dispatcher (T-PLUGIN-02-ADLC-BRIDGE): vendor/adlc/ is a booster-owned static bundle of the 8 adlc verbs booster calls (rails-guard, gate-manifest, flail-detector, hollow-test, consensus-fix, model-router, merge-forecast, ticket), pinned at @adlc/* 1.11.1. It needs no npm install and does no runtime module lookup. The bundled plugin resolves adlc only from here. A digest mismatch fails closed with vendored-adlc-tampered, and every override env var is ignored.

  • scripts/update-adlc-digests.mjs re-pins the vendored digests, but only after checking each source package against its package-lock.json registry integrity.

  • Enforcement gate: when the target repo's active tickets or the plan declare rails, a run whose ticket store is unreadable or whose adlc cannot be authenticated dispatches nothing. A rails-guard operational error mid-run marks the run compromised and blocks every later merge. Audit-only gates (gate-manifest, flail-detector) still only warn. Rails from active store tickets are now enforced post-hoc alongside each plan ticket's own.

  • Post-run integrity check: before dispatch the scheduler snapshots both staged plugins and the host repo's git hooks dir. After each worker it re-checks them, and confirms the worktree still has hooks disabled. Any difference marks the run compromised (report.compromised) and blocks merge.

  • Every agb-spawned agy session is marked as a worker: builders get AGB_WORKER_TICKET=<id>, and review, prosecute, preflight, plan and brain get AGB_WORKER_MODE=readonly. Any other caller defaults to read-only.

  • Plugin decision table (T-PLUGIN-03-DOCTOR-HANDSHAKE): agb bootstrap and agb doctor evaluate the staged adlc-antigravity plugin with one shared evaluator, following the spec §4.4 decision table. The checks run in order: is the manifest valid, is the plugin older than the bundled 1.7.0, does the pinned tree digest match, and finally what contract a newer version declares.

    • Doctor reports not-installed, corrupt-manifest, outdated-plugin, corrupt-tree, incompatible-contract, compatible, compatible (newer-unpinned: vX) or tolerant (unconfirmed-contract).
    • Bootstrap installs, upgrades, reinstalls, keeps, or refuses to touch the plugin to match that row. It re-checks every install, which must end up on a passing row.
  • Policy guard self-test: agb doctor runs the exact hooks.json command under PATH=/usr/bin:/bin against a temporary repo that rails lib/lock.mjs.

    • The write to the rail must be denied with the exact reason, and a write to a non-rail file must produce empty output and exit 0.
    • Doctor records rails-guard-health.json as an informational log only. Nothing reads it.
  • agb doctor now warns about an npm-global agb on PATH (prefer ~/.local/bin/agb), about uses of the AGB_HOOK_DISABLE killswitch logged in hooks.log, and about leftover probe-* plugins.

  • agb migrate (T-PLUGIN-04-MIGRATE-ROLLBACK-DOCS) moves an npm-global or checkout install onto the native plugin through resumable recorded states. It snapshots the staged plugins (excluding node_modules/, .worktrees/ and .git/, capped at 100 MB), the terminal shim, the plugins' import_manifest.json entries and every ~/.gemini/skills link, and writes a read-only pre-migration.baseline.json once. Only links into booster or adlc-antigravity are removed; links to your own skills are never touched.

  • agb migrate --rollback follows the spec's rollback-from-each-state table and restores only from the baseline. It needs --force-rollback when the staged plugins changed after migration, warns when no agb will remain on PATH, and hands the held lock to a detached --finish-uninstall child (2.0 s acknowledgement, otherwise the child is killed and the lock released) when booster was not installed before.

  • lib/migration-lock.mjs: a user-global lock that detects PID reuse by process start time and reclaims a dead holder with an ABA-safe rename. A live holder is never stolen. agb migrate --break-lock clears a wedged lock after confirmation.

  • README, USAGE and ARCHITECTURE document the git-URL install, agb migrate, the slash-command model, and the print-mode residual risk (agy -p turns ask into allow, so in-session protection there is deny-only).

Fixed

  • Structured agy calls work under the live policy guard (T-POLICY-GUARD-AGY-FINISH): with --json-schema, agy 1.3.1 returns the answer through its terminal finish step. The PreToolUse guard treated finish as an unknown tool, so it was denied in read-only worker sessions, for headless builders in ADLC repos, and in repos with active rails. Preflight coldstart, plan, review and prosecution therefore looped and returned no structured_output. finish is now a control step that passes, and its answer text is not scanned for paths. Lookalike tool names are still unknown.
  • Quota probe works against real agy 1.3.1 (T-QUOTA-PROBE-AGY-JSON): agy -p /quota prints a plain-text table, so every probe failed to parse and preflight, plan, review and dispatch halted with "quota telemetry unavailable from agy". The probe now passes --output-format json and reads command.data.groups[].buckets[]. A missing or duplicate window, a non-SUCCESS status, or a remaining_fraction outside [0, 1] still fails closed. The probe timeout rose from 10 s to 30 s. test/fixtures/fake-agy now prints the real formats.
  • The installed plugin can run adlc again (T-PLUGIN-05-VENDORED-ADLC-SPAWN, found by the real-machine migration). The check every adlc call makes just before spawning only accepted an @adlc/cli npm package, so it rejected booster's own vendored copy (@adlc/cli-vendored-by-antigravity-booster). As a result agb run, review, plan, preflight, prosecute and doctor's adlc CLI check all failed in the bundled plugin. The spawn-time check now re-verifies the vendored copy against its pinned digests, and in the bundled plugin it refuses any other binary.

Removed

  • The legacy .agents/ tree (agb-legacy-shim plugin, old agent configs and the duplicate dashboard sidecars). The root commands/, agents/ and top-level sidecars/ are the only sources.

Changed

  • The legacy auto-approve-tests hook is removed. Interactive test runs in repos with active rails now ask for confirmation.
  • package.json bin.agb points at dist/agb.mjs, and @adlc/* are exact-pinned devDependencies.
  • AGENTS.md and docs/guidelines.md record the owner-approved doctrine amendment for vendoring pristine registry tarballs and fail-closed enforcement gates.
  • readPluginContract returns the spec §4.4 status set: unreadable, corrupt (invalid JSON, not an object, or no strict semver version), tolerant (no adlcContract; replaces missing-field), compatible and incompatible. Consumers keep their existing degrade behaviour.
  • In bundled mode AGB_PLUGIN_DIR is ignored. Unbundled runs can point the vendored-adlc lookup elsewhere with AGB_PLUGIN_ROOT (development and tests only).
  • agb doctor exits 1 (was 2) when any check fails. It now checks the staged plugin under ~/.gemini/config/plugins/adlc-antigravity rather than the npm or sibling source copy.
  • An already-staged adlc-antigravity is no longer left in place unconditionally. Bootstrap now follows the decision table, so it upgrades an older or tampered plugin automatically, and refuses to touch a corrupt manifest or a newer incompatible plugin unless --force-reinstall is given.
  • ADLC_ANTIGRAVITY_PLUGIN_PATH is honoured only in unbundled runs with AGB_DEV_ALLOW_UNVERIFIED_PLUGIN=1.

[0.8.0] — 2026-10-03

Added

  • Antigravity 1.2.8 & ADLC 1.11.1 Modernization: Upgraded core runtime and orchestration to support Google Antigravity CLI (agy >= 1.2.8) and the Agentic Development Lifecycle (@adlc >= 1.11.1).
  • Model Catalog & Quota Routing: Integrated Gemini 3.8/3.7/3.6 model tiers; retired Gemini 3.5 variants; implemented dual-pool quota routing dividing Gemini and Claude/GPT-OSS model pools.
  • Structured Subprocess Protocol: Integrated agy --output-format stream-json and --json-schema validation with watchdog controls for line length and total stream bytes.
  • Hardened Platform Sandboxing:
    • Linux: Bubblewrap (bwrap) containment with read-only root mounts, masked .gnupg and host credentials, and loopback network denial.
    • macOS: Hardened Seatbelt profile enforcing strict worktree write containment and credential masking while supporting standard Darwin process execution.
    • Windows: AppContainer differential sandbox probing and replay-defended attestation nonces.
  • Transactional Attempt Databases: Added per-attempt bare Git databases with external gitdir alternates, preventing worktree leakage and ensuring clean atomic rollbacks.
  • Modernization Skill (skills/modernize/): Added automated 5-stage verification audit checking live environment compatibility, dependencies, architectural pillars, and cryptographic provenance.

Changed

  • The ADLC directory ticket store (.adlc/tickets/) is now the canonical projection target. agb plan and the per-worktree rail projection write the directory store (one canonical JSON shard per ticket beside a .store.json manifest) on new repos, and keep writing a legacy .adlc/tickets.json only where one is already checked in (1.x bridge) — never both, since the adlc-antigravity plugin's reader fails closed when both stores exist. agb doctor gained a Ticket Store check that reports the detected backend and fails on the both-stores state. This repo's own workspace migrated via adlc ticket store migrate. In-session rail enforcement on directory-store repos requires the @adlc/antigravity plugin ≥ 1.6.0 (older plugins degrade to the scheduler's post-hoc enforcement).
  • ensureGitignore now writes the full canonical ADLC stanza into target repos (negating .adlc/tickets/, .adlc/ticket-archive/, .adlc/specs/, and .adlc/config.json), matching adlc ticket store migrate and the plugin's adlc-init.
  • @adlc/core and @adlc/antigravity upgraded to 1.11.1; @adlc/tickets added as a direct dependency; CI installs @adlc/cli@1.6.0.
  • Modernized documentation and added comparison matrix with built-in /boost command.

[0.7.0] — 2026-07-21

Breaking

  • agb tui and agb status --ui have been permanently removed. The terminal UI was limited by terminal rendering engines and could not safely run in the background. It has been completely replaced by the Antigravity Sidecar dashboard.

Added

  • Native Antigravity Plugin Support: antigravity-booster is now officially an Antigravity Plugin.
  • Sidecar GUI Plugin: You can now run agb sidecar <repo> and point the Antigravity UI to it via the AGB Dashboard panel. Port flexibility is supported (AGB_SIDECAR_PORT or --port), though the GUI manifest defaults to 3333. Note that starting the server requires --unsafe-open to acknowledge the unauthenticated local HTTP exposure of private logs.

Fixed

  • XSS & Path Traversal Prevention: The new sidecar server blocks path traversal attempts from the browser, and the dashboard DOM safely escapes all inputs from model payloads to prevent Cross-Site Scripting. CSP headers have been hardened by dropping unsafe-inline scripts.
  • Improved Sidecar Log Tail: The events.jsonl reader tracks true file offsets so the dashboard polls efficiently across long 20,000+ event orchestration runs, including gracefully clamping negative or NaN bounds.
  • Dashboard Stability: Fixed crashes in the browser panel caused by unstringified model error payloads, ensuring strikes are rendered rather than silently dropping dashboard updates.

[0.5.1] — 2026-07-19

Fixed

  • A run whose repo lock was stolen mid-flight now aborts instead of reverting a checkout it no longer owns. acquireRepoLock confirmed ownership once, at acquire time, and never re-checked. Because the stale-lock reclaim path can hand the lock to a second live process, the robbed run carried on and ran git reset --hard on a repo another run had taken over — the exact corruption the lock exists to prevent. Ownership is now re-verified in the merge critical section, alongside the branch and dirty-tree checks that were already there, and a lost lock fails the ticket rather than the repository.

Known issues

  • Two concurrent runs can still acquire the same repo lock. The reclaim path moves the lock out of its canonical path before verifying it is still the stale lock it read; while it is moved aside, the mkdir exclusion the scheme relies on is void. Re-verifying immediately before that move narrows the window but cannot close it — POSIX has no compare-and-swap on file content — so a real fix means changing the lock primitive. The guard above bounds the damage to a failed run in the meantime. Tracked in #54.

[0.5.0] — 2026-07-17

Breaking

  • Node 22.19.0 or newer is now required (engines.node moves from >=18). The TUI is now built on @earendil-works/pi-tui, whose own floor is >=22.19.0. Node 18 and 20 are both past end-of-life (2025-04-30 and 2026-04-30). Stay on 0.4.x if you need them. The CI matrix drops to [22] to match.
  • agb tui and agb status --watch --ui no longer use the alternate screen. The dashboard renders into normal scrollback, so it neither clears the screen on entry nor erases itself on exit; the final frame stays in your scrollback.

Fixed

  • The TUI no longer flickers. It had no frame-committing layer at all: every tick wrote a full frame with stdout.write('\x1b[H' + frame) at 10fps, unconditionally, with the cursor visible and no synchronized-output markers. An idle dashboard wrote 212,600 bytes per 10 seconds while zero of its 24 lines had changed. Rendering is now differential (only changed lines are written), wrapped in DECSET 2026 so terminals present frames atomically, and request-driven rather than timer-driven — an unchanged dashboard now writes nothing at all.
  • The TUI no longer garbles or scrolls on non-ASCII agent output. padTruncate measured columns with String.length, counting a CJK grapheme as one column when it occupies two. A transcript containing Japanese text rendered a 115-column line into an 80-column viewport, which wrapped, pushed the frame down and scrolled the buffer on every repaint. Column math now runs through visibleWidth/sliceByColumn, which are grapheme-aware — so emoji are also no longer split mid-surrogate into invalid UTF-8.
  • Long runs no longer degrade the TUI. The in-memory event list grew without bound and every frame rebuilt strings from the entire history to display ~11 lines (12.21ms/frame at 20,000 events). It is now a bounded ring buffer.
  • The cursor is restored on every TUI exit path, including SIGINT/SIGTERM and crashes, rather than leaving the terminal with a hidden cursor.

Changed

  • agb status --watch --interval now sets how often the run is polled for new data; it no longer sets a repaint rate, because repaints are driven by state changes.

0.4.3 — 2026-07-16

Fixed

  • agb doctor: checkAgyAuth no longer hangs when no TTY is attached. The agy models invocation is now wrapped with script on macOS and Linux to allocate a PTY, so background telemetry cannot block it indefinitely. The check timeout also rises from 5s to 15s to tolerate slow network responses.

0.4.2 — 2026-07-15

Fixed

  • agb doctor: Fixed checkPlugin logic and contract checking so that valid plugin installations are correctly recognized instead of triggering the legacy version warning.

0.4.1 — 2026-07-15

Fixed

  • CI / Publish Workflow: Add missing adlc CLI installation to the publish workflow, resolving ENOENT test failures during npm publish.

0.4.0 — 2026-07-15

Added

  • agb tui — full-screen, zero-dependency dashboard reading live from events.jsonl, plus agb status --watch --ui.
  • agb --version (also -v, version).
  • Per-run events.jsonl append-only event log, and per-ticket transcripts normalised to JSONL.
  • Project isolation for runAgy, allowing per-run boundaries.
  • SECURITY.md (disclosure process and threat model), CONTRIBUTING.md, and this changelog.
  • CI now runs on macOS as well as Linux, across Node 18/20/22. The macOS leg exercises the sandbox-exec gate-sandbox tests, which skip on Linux and so had never run in CI.

Fixed

  • Run state and transcripts are now written owner-only (0600). They record full prompts and model output, which can quote secrets read from the worktree; previously they were world-readable.
  • @adlc/core and @adlc/antigravity upgraded to 1.4.1. The plugin manifest declares adlcContract: 1 from 1.4.0, so the bootstrap handshake now reports compatible and live rail enforcement is active instead of degrading to tolerant mode.
  • Documentation corrected: agb status was described as a live full-screen dashboard (it is a one-shot render), the plugin was described as unpublished, and the README opened with a link to a repo no public reader can access.
  • The published package no longer ships the test suite, CI config, or development scratch — files is scoped to what the CLI needs at runtime.
  • The test suite no longer writes scratch files into the working tree.

Security

  • Merge-gate, worktree rebase-conflict, and DAG-ordering guards are now covered by tests verified to fail when the guard is removed. Previously all three could be deleted with the suite fully green.

0.3.1 — 2026-06-22

Patch release.

0.3.0 — 2026-06-22

ADLC alignment: the toolkit is consumed from the @adlc/* npm packages rather than a sibling checkout.

0.2.0 — 2026-06-11

First public release: ticket-DAG scheduler, quota-pool-aware dispatch, worktree fleets, cross-model prosecution, and deterministic gates.

On this page