Release 0.239
0.239.13: the Mantle logo files are back in brand/
The Mantle marks left this repo with the jackdaw split and were later
deleted from jackdaw too, so no repo held a canonical copy. brand/ holds
them again, restored unchanged from git history, with the Affinity design
source (brand/mantle-logo-design.af) they were exported from.
brand/README.md names the source and records where the files went.
0.239.10: the service switches live at Settings > Services
The sandbox and media switches moved off the dashboard to their own screen,
/settings/services (shared nav, Power icon, a help topic). The sandbox and
media refusals and the docs point there. docs/services.md.
0.239.9: app builds accept type-only imports
lintRuntimeImports read import type { ReactNode } from 'react' as a value
import (and { type X } as a name type X), so an app with type-only
imports failed to build. Type-only clauses and specifiers are skipped now; a
mixed import still checks its value names.
0.239.4: a service switch’s .env backups belong to the stack owner
backups/env was made by the root sidecar with umask 077, so the box owner
could not read their own .env backups without sudo. The directories now
go to the stack directory’s owner, as the pre-roll backup’s do.
0.239.3: switch sandboxes or media on and off through the updater
- The updater takes one new request kind, in its own file
(
/signal/service-request.json, so an older updater never takes it for a roll): a service (sandboxesormedia) and on or off. - On: a free-disk check,
.envbacked up tobackups/env(newest 5), the token and sandboxes directory written when missing, the profile added, only that service pulled and started (--no-deps), then a health wait. Any failure restores.envand stops the container again. - Off: running sandbox containers are stopped (never removed), the service container is stopped and removed, the profile dropped. Tokens, the sandboxes directory, every sandbox’s files, app data and images stay.
- Routes (admin logins):
GET /api/services(state, plain descriptions with download size and memory, the small-box warning, the current run),GET /api/services/status(progress),POST /api/services/:name { enable }, audited asservice.toggle. A switch is refused while a roll runs, and a roll while a switch runs. The brain offers the switch only when the updater advertises the verb. - docs/services.md (new); sandboxes.md, video-ingest.md and self-hosting.md point at it.
0.239.2: outside Claude learns how a mini app knows who runs it
An MCP client building an app had no way to learn about host.me(); only
the in-brain app_authoring skill taught it.
app_createcarries a short runtime hint:host.me(), the:host_me_*parameters with a SQL example,host.db,host.tools.callwithapp_tools_set, and the level rules.app_file_writeandapp_source_setpoint at it;app_tools_set,app_db_schema_setandapp_db_querysay the rules that touch them.app_authoring_guide(new, MCP only, read only) serves docs/app-authoring-guide.md whole or one section. The admin server instructions point at it.- Docs drift fixed: the guide said a team app cannot learn the member, and that share links and members never call outside tools (External access says otherwise). The Appsmith skill states the current levels.
0.239.1: the boot reconcile keeps the owner’s param switches
syncSpecialistDefs wrote the manifest params whole onto every enabled
specialist, so a tool_loading, suggest_follow_up or top_p the owner
set went back to the manifest on the next boot. Those three keys
(OWNER_PARAM_KEYS) now keep their stored value; the manifest still owns
temperature and max_tokens. Adopt from template follows the same rule.
The compare ignores jsonb key order, so a row is no longer rewritten on
order alone. The propagation table in
server/web/lib/system-manifest/CLAUDE.md names the kept keys.
0.239.0: one live source for whether sandboxes and media are on
serviceEnabled()(@mantle/config) answers for the dashboard pills,/api/sandboxes, the sandbox tools,video_ingest, the CAD render path and the agent tool list, instead of a check for a bearer token. On means the compose profile is active (the updater’s live/signal/services.json, else the container’sCOMPOSE_PROFILES) and the URL and token are set.- A service that is off shows a grey pill, not red.
- An agent is not offered
sandbox_*orvideo_ingestwhere the service is off (effectiveToolSlugsdrops them; the grant stays). - The updater writes
/signal/services.json(profiles, token presence, container state, host memory, disk, core shape, verbs) withstack.json. Every app service mounts/signalread only. - Both service tokens are made on a roll and on install, so a later switch starts one container instead of restarting the brain. Never rotated.