Skip to content

Release 0.239

0.239.13: the Mantle logo files are back in brand/

The Mantle marks left this repo with the jackdaw split and were later deleted from jackdaw too, so no repo held a canonical copy. brand/ holds them again, restored unchanged from git history, with the Affinity design source (brand/mantle-logo-design.af) they were exported from. brand/README.md names the source and records where the files went.

0.239.10: the service switches live at Settings > Services

The sandbox and media switches moved off the dashboard to their own screen, /settings/services (shared nav, Power icon, a help topic). The sandbox and media refusals and the docs point there. docs/services.md.

0.239.9: app builds accept type-only imports

lintRuntimeImports read import type { ReactNode } from 'react' as a value import (and { type X } as a name type X), so an app with type-only imports failed to build. Type-only clauses and specifiers are skipped now; a mixed import still checks its value names.

0.239.4: a service switch’s .env backups belong to the stack owner

backups/env was made by the root sidecar with umask 077, so the box owner could not read their own .env backups without sudo. The directories now go to the stack directory’s owner, as the pre-roll backup’s do.

0.239.3: switch sandboxes or media on and off through the updater

  • The updater takes one new request kind, in its own file (/signal/service-request.json, so an older updater never takes it for a roll): a service (sandboxes or media) and on or off.
  • On: a free-disk check, .env backed up to backups/env (newest 5), the token and sandboxes directory written when missing, the profile added, only that service pulled and started (--no-deps), then a health wait. Any failure restores .env and stops the container again.
  • Off: running sandbox containers are stopped (never removed), the service container is stopped and removed, the profile dropped. Tokens, the sandboxes directory, every sandbox’s files, app data and images stay.
  • Routes (admin logins): GET /api/services (state, plain descriptions with download size and memory, the small-box warning, the current run), GET /api/services/status (progress), POST /api/services/:name { enable }, audited as service.toggle. A switch is refused while a roll runs, and a roll while a switch runs. The brain offers the switch only when the updater advertises the verb.
  • docs/services.md (new); sandboxes.md, video-ingest.md and self-hosting.md point at it.

0.239.2: outside Claude learns how a mini app knows who runs it

An MCP client building an app had no way to learn about host.me(); only the in-brain app_authoring skill taught it.

  • app_create carries a short runtime hint: host.me(), the :host_me_* parameters with a SQL example, host.db, host.tools.call with app_tools_set, and the level rules. app_file_write and app_source_set point at it; app_tools_set, app_db_schema_set and app_db_query say the rules that touch them.
  • app_authoring_guide (new, MCP only, read only) serves docs/app-authoring-guide.md whole or one section. The admin server instructions point at it.
  • Docs drift fixed: the guide said a team app cannot learn the member, and that share links and members never call outside tools (External access says otherwise). The Appsmith skill states the current levels.

0.239.1: the boot reconcile keeps the owner’s param switches

syncSpecialistDefs wrote the manifest params whole onto every enabled specialist, so a tool_loading, suggest_follow_up or top_p the owner set went back to the manifest on the next boot. Those three keys (OWNER_PARAM_KEYS) now keep their stored value; the manifest still owns temperature and max_tokens. Adopt from template follows the same rule. The compare ignores jsonb key order, so a row is no longer rewritten on order alone. The propagation table in server/web/lib/system-manifest/CLAUDE.md names the kept keys.

0.239.0: one live source for whether sandboxes and media are on

  • serviceEnabled() (@mantle/config) answers for the dashboard pills, /api/sandboxes, the sandbox tools, video_ingest, the CAD render path and the agent tool list, instead of a check for a bearer token. On means the compose profile is active (the updater’s live /signal/services.json, else the container’s COMPOSE_PROFILES) and the URL and token are set.
  • A service that is off shows a grey pill, not red.
  • An agent is not offered sandbox_* or video_ingest where the service is off (effectiveToolSlugs drops them; the grant stays).
  • The updater writes /signal/services.json (profiles, token presence, container state, host memory, disk, core shape, verbs) with stack.json. Every app service mounts /signal read only.
  • Both service tokens are made on a roll and on install, so a later switch starts one container instead of restarting the brain. Never rotated.