Changelog
Release history, generated from CHANGELOG.md.
Notable changes to antigravity-booster. Versioning follows semver from
1.0.0 — see Stability.
The format follows Keep a Changelog. Entries before 0.4.0 were reconstructed from git history, so they summarise rather than enumerate.
Unreleased
[1.0.0] — 2026-10-08
booster is now a native Antigravity plugin. Install it with
agy plugin install <git-url>, with no npm install step. Existing npm-global
or checkout installs move over with agb migrate, and agb migrate --rollback
reverses that. A unified PreToolUse policy guard now enforces frozen rails and
the ADLC trust root inside every agy session. adlc ships vendored and
digest-pinned, so the plugin is self-contained. This release was validated with
a full migrate, doctor, live rail denial, rollback and re-migrate cycle on a
real machine against agy 1.3.1.
Breaking: the legacy auto-approve-tests hook and the .agents/ tree are
gone, agb doctor exits 1 (was 2) on failure, and bin.agb now points at
dist/agb.mjs. See Removed and Changed below.
Added
-
Native Antigravity plugin layout (T-PLUGIN-01-CORE):
agy plugin install <git-url>now stages a complete plugin with nonpm install. Prebuilt bundles are committed underdist/(agb.mjs,mcp-server.mjs,hooks/pre-tool-use.bundle.mjs) and contain only Node built-ins. Rootcommands/,agents/,hooks.jsonandmcp_config.jsonreplace.agents/plugins/agb, which remains as a hooklessagb-legacy-shimuntil the migration ticket. -
Unified PreToolUse policy guard: frozen rails and the ADLC trust root (
.adlc/config.json, the manifest, ticket shards,.git/) are denied in-session. Unlisted shell commandsaskin repos with active rails. Booster never emitsallow. It runs behindbin/hook-runner.sh, a fail-safe runner with a 9 s watchdog, andbin/node-launcher.sh, which finds a trusted Node >= 22.19 under a stripped GUI PATH. -
agb bootstrapinstalls@adlc/antigravityfrom the vendored, integrity-pinned npm tarball and writes the~/.local/bin/agbterminal shim. New--force-reinstallflag. -
CI
plugin-integrityjob: bundle drift gate, shellcheck, and a byte-identity check of the vendored tarball against the npm release. -
Vendored
adlcdispatcher (T-PLUGIN-02-ADLC-BRIDGE):vendor/adlc/is a booster-owned static bundle of the 8adlcverbs booster calls (rails-guard,gate-manifest,flail-detector,hollow-test,consensus-fix,model-router,merge-forecast,ticket), pinned at@adlc/*1.11.1. It needs nonpm installand does no runtime module lookup. The bundled plugin resolvesadlconly from here. A digest mismatch fails closed withvendored-adlc-tampered, and every override env var is ignored. -
scripts/update-adlc-digests.mjsre-pins the vendored digests, but only after checking each source package against itspackage-lock.jsonregistry integrity. -
Enforcement gate: when the target repo's active tickets or the plan declare rails, a run whose ticket store is unreadable or whose
adlccannot be authenticated dispatches nothing. A rails-guard operational error mid-run marks the run compromised and blocks every later merge. Audit-only gates (gate-manifest,flail-detector) still only warn. Rails from active store tickets are now enforced post-hoc alongside each plan ticket's own. -
Post-run integrity check: before dispatch the scheduler snapshots both staged plugins and the host repo's git hooks dir. After each worker it re-checks them, and confirms the worktree still has hooks disabled. Any difference marks the run compromised (
report.compromised) and blocks merge. -
Every agb-spawned
agysession is marked as a worker: builders getAGB_WORKER_TICKET=<id>, and review, prosecute, preflight, plan and brain getAGB_WORKER_MODE=readonly. Any other caller defaults to read-only. -
Plugin decision table (T-PLUGIN-03-DOCTOR-HANDSHAKE):
agb bootstrapandagb doctorevaluate the stagedadlc-antigravityplugin with one shared evaluator, following the spec §4.4 decision table. The checks run in order: is the manifest valid, is the plugin older than the bundled 1.7.0, does the pinned tree digest match, and finally what contract a newer version declares.- Doctor reports
not-installed,corrupt-manifest,outdated-plugin,corrupt-tree,incompatible-contract,compatible,compatible (newer-unpinned: vX)ortolerant (unconfirmed-contract). - Bootstrap installs, upgrades, reinstalls, keeps, or refuses to touch the plugin to match that row. It re-checks every install, which must end up on a passing row.
- Doctor reports
-
Policy guard self-test:
agb doctorruns the exacthooks.jsoncommand underPATH=/usr/bin:/binagainst a temporary repo that railslib/lock.mjs.- The write to the rail must be denied with the exact reason, and a write to a non-rail file must produce empty output and exit 0.
- Doctor records
rails-guard-health.jsonas an informational log only. Nothing reads it.
-
agb doctornow warns about an npm-globalagbon PATH (prefer~/.local/bin/agb), about uses of theAGB_HOOK_DISABLEkillswitch logged inhooks.log, and about leftoverprobe-*plugins. -
agb migrate(T-PLUGIN-04-MIGRATE-ROLLBACK-DOCS) moves an npm-global or checkout install onto the native plugin through resumable recorded states. It snapshots the staged plugins (excludingnode_modules/,.worktrees/and.git/, capped at 100 MB), the terminal shim, the plugins'import_manifest.jsonentries and every~/.gemini/skillslink, and writes a read-onlypre-migration.baseline.jsononce. Only links into booster or adlc-antigravity are removed; links to your own skills are never touched. -
agb migrate --rollbackfollows the spec's rollback-from-each-state table and restores only from the baseline. It needs--force-rollbackwhen the staged plugins changed after migration, warns when noagbwill remain on PATH, and hands the held lock to a detached--finish-uninstallchild (2.0 s acknowledgement, otherwise the child is killed and the lock released) when booster was not installed before. -
lib/migration-lock.mjs: a user-global lock that detects PID reuse by process start time and reclaims a dead holder with an ABA-safe rename. A live holder is never stolen.agb migrate --break-lockclears a wedged lock after confirmation. -
README, USAGE and ARCHITECTURE document the git-URL install,
agb migrate, the slash-command model, and the print-mode residual risk (agy -pturnsaskinto allow, so in-session protection there is deny-only).
Fixed
- Structured agy calls work under the live policy guard (T-POLICY-GUARD-AGY-FINISH): with
--json-schema, agy 1.3.1 returns the answer through its terminalfinishstep. The PreToolUse guard treatedfinishas an unknown tool, so it was denied in read-only worker sessions, for headless builders in ADLC repos, and in repos with active rails. Preflight coldstart, plan, review and prosecution therefore looped and returned nostructured_output.finishis now a control step that passes, and its answer text is not scanned for paths. Lookalike tool names are still unknown. - Quota probe works against real agy 1.3.1 (T-QUOTA-PROBE-AGY-JSON):
agy -p /quotaprints a plain-text table, so every probe failed to parse and preflight, plan, review and dispatch halted with "quota telemetry unavailable from agy". The probe now passes--output-format jsonand readscommand.data.groups[].buckets[]. A missing or duplicate window, a non-SUCCESS status, or aremaining_fractionoutside [0, 1] still fails closed. The probe timeout rose from 10 s to 30 s.test/fixtures/fake-agynow prints the real formats. - The installed plugin can run
adlcagain (T-PLUGIN-05-VENDORED-ADLC-SPAWN, found by the real-machine migration). The check everyadlccall makes just before spawning only accepted an@adlc/clinpm package, so it rejected booster's own vendored copy (@adlc/cli-vendored-by-antigravity-booster). As a resultagb run, review, plan, preflight, prosecute and doctor'sadlc CLIcheck all failed in the bundled plugin. The spawn-time check now re-verifies the vendored copy against its pinned digests, and in the bundled plugin it refuses any other binary.
Removed
- The legacy
.agents/tree (agb-legacy-shimplugin, old agent configs and the duplicate dashboard sidecars). The rootcommands/,agents/and top-levelsidecars/are the only sources.
Changed
- The legacy
auto-approve-testshook is removed. Interactive test runs in repos with active rails now ask for confirmation. package.jsonbin.agbpoints atdist/agb.mjs, and@adlc/*are exact-pinneddevDependencies.- AGENTS.md and docs/guidelines.md record the owner-approved doctrine amendment for vendoring pristine registry tarballs and fail-closed enforcement gates.
readPluginContractreturns the spec §4.4 status set:unreadable,corrupt(invalid JSON, not an object, or no strict semverversion),tolerant(noadlcContract; replacesmissing-field),compatibleandincompatible. Consumers keep their existing degrade behaviour.- In bundled mode
AGB_PLUGIN_DIRis ignored. Unbundled runs can point the vendored-adlclookup elsewhere withAGB_PLUGIN_ROOT(development and tests only). agb doctorexits 1 (was 2) when any check fails. It now checks the staged plugin under~/.gemini/config/plugins/adlc-antigravityrather than the npm or sibling source copy.- An already-staged
adlc-antigravityis no longer left in place unconditionally. Bootstrap now follows the decision table, so it upgrades an older or tampered plugin automatically, and refuses to touch a corrupt manifest or a newer incompatible plugin unless--force-reinstallis given. ADLC_ANTIGRAVITY_PLUGIN_PATHis honoured only in unbundled runs withAGB_DEV_ALLOW_UNVERIFIED_PLUGIN=1.
[0.8.0] — 2026-10-03
Added
- Antigravity 1.2.8 & ADLC 1.11.1 Modernization: Upgraded core runtime and orchestration to support Google Antigravity CLI (
agy >= 1.2.8) and the Agentic Development Lifecycle (@adlc >= 1.11.1). - Model Catalog & Quota Routing: Integrated Gemini 3.8/3.7/3.6 model tiers; retired Gemini 3.5 variants; implemented dual-pool quota routing dividing Gemini and Claude/GPT-OSS model pools.
- Structured Subprocess Protocol: Integrated
agy --output-format stream-jsonand--json-schemavalidation with watchdog controls for line length and total stream bytes. - Hardened Platform Sandboxing:
- Linux: Bubblewrap (
bwrap) containment with read-only root mounts, masked.gnupgand host credentials, and loopback network denial. - macOS: Hardened Seatbelt profile enforcing strict worktree write containment and credential masking while supporting standard Darwin process execution.
- Windows: AppContainer differential sandbox probing and replay-defended attestation nonces.
- Linux: Bubblewrap (
- Transactional Attempt Databases: Added per-attempt bare Git databases with external gitdir alternates, preventing worktree leakage and ensuring clean atomic rollbacks.
- Modernization Skill (
skills/modernize/): Added automated 5-stage verification audit checking live environment compatibility, dependencies, architectural pillars, and cryptographic provenance.
Changed
- The ADLC directory ticket store (
.adlc/tickets/) is now the canonical projection target.agb planand the per-worktree rail projection write the directory store (one canonical JSON shard per ticket beside a.store.jsonmanifest) on new repos, and keep writing a legacy.adlc/tickets.jsononly where one is already checked in (1.x bridge) — never both, since the adlc-antigravity plugin's reader fails closed when both stores exist.agb doctorgained a Ticket Store check that reports the detected backend and fails on the both-stores state. This repo's own workspace migrated viaadlc ticket store migrate. In-session rail enforcement on directory-store repos requires the@adlc/antigravityplugin ≥ 1.6.0 (older plugins degrade to the scheduler's post-hoc enforcement). ensureGitignorenow writes the full canonical ADLC stanza into target repos (negating.adlc/tickets/,.adlc/ticket-archive/,.adlc/specs/, and.adlc/config.json), matchingadlc ticket store migrateand the plugin'sadlc-init.@adlc/coreand@adlc/antigravityupgraded to 1.11.1;@adlc/ticketsadded as a direct dependency; CI installs@adlc/cli@1.6.0.- Modernized documentation and added comparison matrix with built-in
/boostcommand.
[0.7.0] — 2026-07-21
Breaking
agb tuiandagb status --uihave been permanently removed. The terminal UI was limited by terminal rendering engines and could not safely run in the background. It has been completely replaced by the Antigravity Sidecar dashboard.
Added
- Native Antigravity Plugin Support:
antigravity-boosteris now officially an Antigravity Plugin. - Sidecar GUI Plugin: You can now run
agb sidecar <repo>and point the Antigravity UI to it via the AGB Dashboard panel. Port flexibility is supported (AGB_SIDECAR_PORTor--port), though the GUI manifest defaults to3333. Note that starting the server requires--unsafe-opento acknowledge the unauthenticated local HTTP exposure of private logs.
Fixed
- XSS & Path Traversal Prevention: The new sidecar server blocks path traversal attempts from the browser, and the dashboard DOM safely escapes all inputs from model payloads to prevent Cross-Site Scripting. CSP headers have been hardened by dropping
unsafe-inlinescripts. - Improved Sidecar Log Tail: The
events.jsonlreader tracks true file offsets so the dashboard polls efficiently across long 20,000+ event orchestration runs, including gracefully clamping negative or NaN bounds. - Dashboard Stability: Fixed crashes in the browser panel caused by unstringified model error payloads, ensuring strikes are rendered rather than silently dropping dashboard updates.
[0.5.1] — 2026-07-19
Fixed
- A run whose repo lock was stolen mid-flight now aborts instead of reverting
a checkout it no longer owns.
acquireRepoLockconfirmed ownership once, at acquire time, and never re-checked. Because the stale-lock reclaim path can hand the lock to a second live process, the robbed run carried on and rangit reset --hardon a repo another run had taken over — the exact corruption the lock exists to prevent. Ownership is now re-verified in the merge critical section, alongside the branch and dirty-tree checks that were already there, and a lost lock fails the ticket rather than the repository.
Known issues
- Two concurrent runs can still acquire the same repo lock. The reclaim path
moves the lock out of its canonical path before verifying it is still the
stale lock it read; while it is moved aside, the
mkdirexclusion the scheme relies on is void. Re-verifying immediately before that move narrows the window but cannot close it — POSIX has no compare-and-swap on file content — so a real fix means changing the lock primitive. The guard above bounds the damage to a failed run in the meantime. Tracked in #54.
[0.5.0] — 2026-07-17
Breaking
- Node 22.19.0 or newer is now required (
engines.nodemoves from>=18). The TUI is now built on@earendil-works/pi-tui, whose own floor is>=22.19.0. Node 18 and 20 are both past end-of-life (2025-04-30 and 2026-04-30). Stay on0.4.xif you need them. The CI matrix drops to[22]to match. agb tuiandagb status --watch --uino longer use the alternate screen. The dashboard renders into normal scrollback, so it neither clears the screen on entry nor erases itself on exit; the final frame stays in your scrollback.
Fixed
- The TUI no longer flickers. It had no frame-committing layer at all: every
tick wrote a full frame with
stdout.write('\x1b[H' + frame)at 10fps, unconditionally, with the cursor visible and no synchronized-output markers. An idle dashboard wrote 212,600 bytes per 10 seconds while zero of its 24 lines had changed. Rendering is now differential (only changed lines are written), wrapped in DECSET 2026 so terminals present frames atomically, and request-driven rather than timer-driven — an unchanged dashboard now writes nothing at all. - The TUI no longer garbles or scrolls on non-ASCII agent output.
padTruncatemeasured columns withString.length, counting a CJK grapheme as one column when it occupies two. A transcript containing Japanese text rendered a 115-column line into an 80-column viewport, which wrapped, pushed the frame down and scrolled the buffer on every repaint. Column math now runs throughvisibleWidth/sliceByColumn, which are grapheme-aware — so emoji are also no longer split mid-surrogate into invalid UTF-8. - Long runs no longer degrade the TUI. The in-memory event list grew without bound and every frame rebuilt strings from the entire history to display ~11 lines (12.21ms/frame at 20,000 events). It is now a bounded ring buffer.
- The cursor is restored on every TUI exit path, including
SIGINT/SIGTERMand crashes, rather than leaving the terminal with a hidden cursor.
Changed
agb status --watch --intervalnow sets how often the run is polled for new data; it no longer sets a repaint rate, because repaints are driven by state changes.
0.4.3 — 2026-07-16
Fixed
- agb doctor:
checkAgyAuthno longer hangs when no TTY is attached. Theagy modelsinvocation is now wrapped withscripton macOS and Linux to allocate a PTY, so background telemetry cannot block it indefinitely. The check timeout also rises from 5s to 15s to tolerate slow network responses.
0.4.2 — 2026-07-15
Fixed
- agb doctor: Fixed
checkPluginlogic and contract checking so that valid plugin installations are correctly recognized instead of triggering the legacy version warning.
0.4.1 — 2026-07-15
Fixed
- CI / Publish Workflow: Add missing
adlcCLI installation to the publish workflow, resolvingENOENTtest failures duringnpm publish.
0.4.0 — 2026-07-15
Added
agb tui— full-screen, zero-dependency dashboard reading live fromevents.jsonl, plusagb status --watch --ui.agb --version(also-v,version).- Per-run
events.jsonlappend-only event log, and per-ticket transcripts normalised to JSONL. - Project isolation for
runAgy, allowing per-run boundaries. SECURITY.md(disclosure process and threat model),CONTRIBUTING.md, and this changelog.- CI now runs on macOS as well as Linux, across Node 18/20/22. The macOS leg
exercises the
sandbox-execgate-sandbox tests, which skip on Linux and so had never run in CI.
Fixed
- Run state and transcripts are now written owner-only (
0600). They record full prompts and model output, which can quote secrets read from the worktree; previously they were world-readable. @adlc/coreand@adlc/antigravityupgraded to 1.4.1. The plugin manifest declaresadlcContract: 1from 1.4.0, so the bootstrap handshake now reports compatible and live rail enforcement is active instead of degrading to tolerant mode.- Documentation corrected:
agb statuswas described as a live full-screen dashboard (it is a one-shot render), the plugin was described as unpublished, and the README opened with a link to a repo no public reader can access. - The published package no longer ships the test suite, CI config, or
development scratch —
filesis scoped to what the CLI needs at runtime. - The test suite no longer writes scratch files into the working tree.
Security
- Merge-gate, worktree rebase-conflict, and DAG-ordering guards are now covered by tests verified to fail when the guard is removed. Previously all three could be deleted with the suite fully green.
0.3.1 — 2026-06-22
Patch release.
0.3.0 — 2026-06-22
ADLC alignment: the toolkit is consumed from the @adlc/* npm packages rather
than a sibling checkout.
0.2.0 — 2026-06-11
First public release: ticket-DAG scheduler, quota-pool-aware dispatch, worktree fleets, cross-model prosecution, and deterministic gates.